[CLSA-2026:1788800355] Fix CVE(s): CVE-2026-81934
Type:
security
Severity:
Important
Release date:
2026-09-07 16:59:25 UTC
Description:
* SECURITY UPDATE: Use-after-free in tlsProcessPendingData via a pending TLS connection closed from another connection's read handler - debian/patches/CVE-2026-81934.patch: drain the TLS pending list from the head and detach each node before running its handler in tlsProcessPendingData, instead of iterating with a listIter that caches a next pointer which can be freed - CVE-2026-81934
CVEs fixed:
Updated packages:
  • redis6.2_6.2.21-1~trixie+tuxcare.els8_all.deb
    sha:f792a32a65627f2201f81ee56be36446f425aa3e
  • redis6.2-sentinel_6.2.21-1~trixie+tuxcare.els8_amd64.deb
    sha:50ce7bd5d3d9b5fe3a47a38d2f8282bcbba1139f
  • redis6.2-server_6.2.21-1~trixie+tuxcare.els8_amd64.deb
    sha:ad19d8d87422fdbc8b77cb1372bd0ed2ebc4e931
  • redis6.2-tools_6.2.21-1~trixie+tuxcare.els8_amd64.deb
    sha:2392a1f46be6546b3d87689a3eb0f3361f1ddc75
  • redis6.2-sentinel_6.2.21-1~trixie+tuxcare.els8_arm64.deb
    sha:ceeae3ba1c2d2dbc21d6f55b714aba501e2e5ac5
  • redis6.2-server_6.2.21-1~trixie+tuxcare.els8_arm64.deb
    sha:f5874d7ef307316a11c494d4109fc96c47fee038
  • redis6.2-tools_6.2.21-1~trixie+tuxcare.els8_arm64.deb
    sha:984302d80cbec9bc4fcb6cbc2c9df2a44dba5978
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.