[CLSA-2026:1788800150] Fix CVE(s): CVE-2026-81934
Type:
security
Severity:
Important
Release date:
2026-09-07 16:56:00 UTC
Description:
* SECURITY UPDATE: Use-after-free in tlsProcessPendingData() pending-list iteration - debian/patches/CVE-2026-81934.patch: replace the listIter based walk of pending_list with a bounded detach-from-head drain that re-reads listFirst() and unlinks each node before tlsHandleEvent() runs, so a read handler closing a different pending TLS connection can no longer leave the iterator holding a dangling cached next pointer - CVE-2026-81934
CVEs fixed:
Updated packages:
  • redis7_7.0.15-1~bookworm+tuxcare.els10_all.deb
    sha:93e85e4875a5cb6bbd85a119dc1150b38790ae79
  • redis7-sentinel_7.0.15-1~bookworm+tuxcare.els10_amd64.deb
    sha:4fd249f9ea26965460e4a16371c2fc865047f6d8
  • redis7-server_7.0.15-1~bookworm+tuxcare.els10_amd64.deb
    sha:e7ac07525f91eb404fde34845c534bf327d40ddd
  • redis7-tools_7.0.15-1~bookworm+tuxcare.els10_amd64.deb
    sha:75eb011dc1d4901dcb61830f0e8d84e64b4c0d11
  • redis7-sentinel_7.0.15-1~bookworm+tuxcare.els10_arm64.deb
    sha:fd5e9bb418e12067a154f0c5b1f6f322d5d9202d
  • redis7-server_7.0.15-1~bookworm+tuxcare.els10_arm64.deb
    sha:cb43ebdd1256f21f56602e72181ca8e362ca39a4
  • redis7-tools_7.0.15-1~bookworm+tuxcare.els10_arm64.deb
    sha:3a727bfc52f68155058284538ea9bd020d6016dd
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.