FEDORA-2023-c406ba1ff6
Packages in this update:
redis-7.0.12-1.fc38
Update description:
Redis 7.0.12 – Released Mon July 10 12:00:00 IDT 2023
Upgrade urgency SECURITY: See security fixes below.
Security Fixes:
(CVE-2022-24834) A specially crafted Lua script executing in Redis can trigger
a heap overflow in the cjson and cmsgpack libraries, and result in heap
corruption and potentially remote code execution. The problem exists in all
versions of Redis with Lua scripting support, starting from 2.6, and affects
only authenticated and authorized users.
(CVE-2023-36824) Extracting key names from a command and a list of arguments
may, in some cases, trigger a heap overflow and result in reading random heap
memory, heap corruption and potentially remote code execution. Specifically:
using COMMAND GETKEYS* and validation of key names in ACL rules.
Bug Fixes
Re-enable downscale rehashing while there is a fork child (#12276)
Fix possible hang in HRANDFIELD, SRANDMEMBER, ZRANDMEMBER when used with <count> (#12276)
Improve fairness issue in RANDOMKEY, HRANDFIELD, SRANDMEMBER, ZRANDMEMBER, SPOP, and eviction (#12276)
Fix WAIT to be effective after a blocked module command being unblocked (#12220)
Avoid unnecessary full sync after master restart in a rare case (#12088)
More Stories
firefox-134.0-1.fc41
FEDORA-2025-6fcde64d77 Packages in this update: firefox-134.0-1.fc41 Update description: Updated to latest upstream (134.0) Read More
firefox-134.0-1.fc40
FEDORA-2025-e8a71b6caf Packages in this update: firefox-134.0-1.fc40 Update description: Updated to latest upstream (134.0) Read More
seamonkey-2.53.20-1.el8
FEDORA-EPEL-2025-49f65941e5 Packages in this update: seamonkey-2.53.20-1.el8 Update description: Update to 2.53.20 Read More
seamonkey-2.53.20-1.fc40
FEDORA-2025-398837e1d1 Packages in this update: seamonkey-2.53.20-1.fc40 Update description: Update to 2.53.20 Read More
seamonkey-2.53.20-1.fc41
FEDORA-2025-a39068bf59 Packages in this update: seamonkey-2.53.20-1.fc41 Update description: Update to 2.53.20 Read More
USN-7187-1: Linux kernel (OEM) vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This...