Описание
ELSA-2026-64823-0: redis:6 security update (IMPORTANT)
[6.2.24-1.0.1]
- Build with 64k pages to support redis on both UEK6 and UEK7 on aarch64
[6.2.24-1]
- rebase to 6.2.24 for CVE-2026-66373
Обновленные пакеты
Oracle Linux 8
Oracle Linux aarch64
Module redis:6 is enabled
redis
6.2.24-1.0.1.module+el8.10.0+91026+eb7a02a1
redis-devel
6.2.24-1.0.1.module+el8.10.0+91026+eb7a02a1
redis-doc
6.2.24-1.0.1.module+el8.10.0+91026+eb7a02a1
Oracle Linux x86_64
Module redis:6 is enabled
redis
6.2.24-1.0.1.module+el8.10.0+91026+eb7a02a1
redis-devel
6.2.24-1.0.1.module+el8.10.0+91026+eb7a02a1
redis-doc
6.2.24-1.0.1.module+el8.10.0+91026+eb7a02a1
Связанные CVE
Связанные уязвимости
Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands with the privileges of the Redis server. Fixed in Redis 8.2.9, 8.4.6, 8.6.6, 8.8.2, and 8.10.1.