Описание
ELSA-2026-65120-0: redis:7 security update (IMPORTANT)
[7.2.16-1.0.1]
- Build with 64k pages to support redis on UEK on aarch64
[7.2.16-1]
- rebase to 7.2.16 for CVE-2026-66373 and backport CVE-2026-72568
Обновленные пакеты
Oracle Linux 9
Oracle Linux aarch64
Module redis:7 is enabled
redis
7.2.16-1.0.1.module+el9.8.0+91028+45c54649
redis-devel
7.2.16-1.0.1.module+el9.8.0+91028+45c54649
redis-doc
7.2.16-1.0.1.module+el9.8.0+91028+45c54649
Oracle Linux x86_64
Module redis:7 is enabled
redis
7.2.16-1.0.1.module+el9.8.0+91028+45c54649
redis-devel
7.2.16-1.0.1.module+el9.8.0+91028+45c54649
redis-doc
7.2.16-1.0.1.module+el9.8.0+91028+45c54649
Связанные CVE
Связанные уязвимости
Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.