stable

redis-7.0.12-1.fc37

FEDORA-2023-800612d23a created by remi a year ago for Fedora 37

Redis 7.0.12 - Released Mon July 10 12:00:00 IDT 2023

Upgrade urgency SECURITY: See security fixes below.

Security Fixes:

  • (CVE-2022-24834) A specially crafted Lua script executing in Redis can trigger a heap overflow in the cjson and cmsgpack libraries, and result in heap corruption and potentially remote code execution. The problem exists in all versions of Redis with Lua scripting support, starting from 2.6, and affects only authenticated and authorized users.
  • (CVE-2023-36824) Extracting key names from a command and a list of arguments may, in some cases, trigger a heap overflow and result in reading random heap memory, heap corruption and potentially remote code execution. Specifically: using COMMAND GETKEYS* and validation of key names in ACL rules.

Bug Fixes

  • Re-enable downscale rehashing while there is a fork child (#12276)
  • Fix possible hang in HRANDFIELD, SRANDMEMBER, ZRANDMEMBER when used with <count> (#12276)
  • Improve fairness issue in RANDOMKEY, HRANDFIELD, SRANDMEMBER, ZRANDMEMBER, SPOP, and eviction (#12276)
  • Fix WAIT to be effective after a blocked module command being unblocked (#12220)
  • Avoid unnecessary full sync after master restart in a rare case (#12088)

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2023-800612d23a

This update has been submitted for testing by remi.

a year ago

This update's test gating status has been changed to 'ignored'.

a year ago

This update has been pushed to testing.

a year ago

remi edited this update.

a year ago

This update has been submitted for stable by bodhi.

a year ago

This update has been pushed to stable.

a year ago

Please login to add feedback.

Metadata
Type
security
Severity
medium
Karma
0
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
7 days
Dates
submitted
a year ago
in testing
a year ago
in stable
a year ago
modified
a year ago
approved
a year ago
BZ#2221662 CVE-2022-24834 redis: heap overflow in the lua cjson and cmsgpack libraries
0
0
BZ#2221664 CVE-2023-36824 redis: heap overflow in COMMAND GETKEYS and ACL evaluation
0
0
BZ#2222025 TRIAGE-CVE-2022-24834 redis: heap overflow in the lua cjson and cmsgpack libraries [fedora-all]
0
0
BZ#2222026 TRIAGE-CVE-2023-36824 redis: heap overflow in COMMAND GETKEYS and ACL evaluation [fedora-all]
0
0

Automated Test Results