megachangelog
Security7.2.15

Security fix for stream RESTORE use-after-free vulnerability

A crafted stream RESTORE payload could cause two consumers to share the same NACK entry, leading to a use-after-free condition that may result in Remote Code Execution. This security vulnerability has been patched.

Update urgency: SECURITY: There is a security fix in the release.

Security fixes

  • A crafted stream RESTORE payload can make two consumers share the same NACK, leading to a use-after-free that may result in Remote Code Execution
securitystreamrceuse-after-free

Source: original entry ↗