megachangelog
Security6.2.23

Stream RESTORE payload RCE vulnerability fix

Fixed a critical security vulnerability where a crafted stream RESTORE payload could cause two consumers to share the same NACK, leading to use-after-free and potential remote code execution.

Update urgency: SECURITY: There is a security fix in the release.

Security fixes

  • A crafted stream RESTORE payload can make two consumers share the same NACK, leading to a use-after-free that may result in Remote Code Execution
securityrcestreamsvulnerability

Source: original entry ↗