[CLSA-2026:1786713834] Fix CVE(s): CVE-2026-66373
Type:
security
Severity:
Important
Release date:
2026-08-14 13:24:04 UTC
Description:
* SECURITY UPDATE: Double free via a crafted RESTORE payload in which the same stream NACK is referenced by more than one consumer - debian/patches/CVE-2026-66373.patch: reject the payload in rdbLoadObject when a consumer PEL entry references a NACK that already has a consumer assigned - CVE-2026-66373
CVEs fixed:
Updated packages:
  • redis6.2_6.2.21-1~bookworm+tuxcare.els7_all.deb
    sha:0fa8912380e49ed58ec11340c5f90fb3498e1d96
  • redis6.2-sentinel_6.2.21-1~bookworm+tuxcare.els7_amd64.deb
    sha:e629ee5c54233d91296949500861007b11b779f5
  • redis6.2-server_6.2.21-1~bookworm+tuxcare.els7_amd64.deb
    sha:d07f0cdcd7e1bf6c057c0710d01aff7fce4e67cf
  • redis6.2-tools_6.2.21-1~bookworm+tuxcare.els7_amd64.deb
    sha:f45d118606d7dfe2d49ce7d9e715de09c7839aab
  • redis6.2_6.2.21-1~bookworm+tuxcare.els7_all.deb
    sha:0fa8912380e49ed58ec11340c5f90fb3498e1d96
  • redis6.2-sentinel_6.2.21-1~bookworm+tuxcare.els7_arm64.deb
    sha:c5d2f9182da3b35367f83da9d49eb0e6dd65a3ae
  • redis6.2-server_6.2.21-1~bookworm+tuxcare.els7_arm64.deb
    sha:a1900433dab9cf6b678e01d386e6b0973429fac1
  • redis6.2-tools_6.2.21-1~bookworm+tuxcare.els7_arm64.deb
    sha:73df879fe963516c8ea908efa9ce09158b274066
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.