[CLSA-2026:1788799146] Fix CVE(s): CVE-2026-81934
Type:
security
Severity:
Important
Release date:
2026-09-07 16:39:16 UTC
Description:
* SECURITY UPDATE: Use-after-free in tlsProcessPendingData via a pending TLS connection closed from another connection's read handler - debian/patches/CVE-2026-81934.patch: drain the TLS pending list from the head and detach each node before running its handler in tlsProcessPendingData, instead of iterating with a listIter that caches a next pointer which can be freed - CVE-2026-81934
CVEs fixed:
Updated packages:
  • redis6.2_6.2.21-1~bookworm+tuxcare.els8_all.deb
    sha:3fe787cecb9846db78d3ea4c64d5732fb8a19c18
  • redis6.2-sentinel_6.2.21-1~bookworm+tuxcare.els8_amd64.deb
    sha:c4346b3df51e85ce29c89204fb02d152e4e274b2
  • redis6.2-server_6.2.21-1~bookworm+tuxcare.els8_amd64.deb
    sha:aa04c81b2c1903be65367b55acabf840e88116f5
  • redis6.2-tools_6.2.21-1~bookworm+tuxcare.els8_amd64.deb
    sha:4f4683172f6eacf701106a6098baac5998bc90fb
  • redis6.2-sentinel_6.2.21-1~bookworm+tuxcare.els8_arm64.deb
    sha:120b2fef117758ae41d65abf6f61afb376f999bf
  • redis6.2-server_6.2.21-1~bookworm+tuxcare.els8_arm64.deb
    sha:a520233bee23f9c12419dd0d7778cceafd58f864
  • redis6.2-tools_6.2.21-1~bookworm+tuxcare.els8_arm64.deb
    sha:3778db4f8f44ca63c8e4b83224041f0faed48c5c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.