[CLSA-2026:1788799407] Fix CVE(s): CVE-2026-81934
Type:
security
Severity:
Important
Release date:
2026-09-07 16:43:37 UTC
Description:
* SECURITY UPDATE: Use-after-free in tlsProcessPendingData() pending-list iteration - debian/patches/CVE-2026-81934.patch: replace the listIter based walk of pending_list with a bounded detach-from-head drain that re-reads listFirst() and unlinks each node before tlsHandleEvent() runs, so a read handler closing a different pending TLS connection can no longer leave the iterator holding a dangling cached next pointer - CVE-2026-81934
CVEs fixed:
Updated packages:
  • redis7_7.0.15-1~trixie+tuxcare.els10_all.deb
    sha:40eb865d551b1d92c9a402d986c5b2a9109dec57
  • redis7-sentinel_7.0.15-1~trixie+tuxcare.els10_amd64.deb
    sha:5ad1abbac217dea8d3e90ef24dde1fb71c3fa3f8
  • redis7-server_7.0.15-1~trixie+tuxcare.els10_amd64.deb
    sha:b8ae3668e40b22cdd28f08773a1d927ff737e041
  • redis7-tools_7.0.15-1~trixie+tuxcare.els10_amd64.deb
    sha:d8d4ed41e1087e37a2faeea171482b6e434b6c9e
  • redis7-sentinel_7.0.15-1~trixie+tuxcare.els10_arm64.deb
    sha:88a76936eaf48eacbf920aa884e6678ba6e6aea0
  • redis7-server_7.0.15-1~trixie+tuxcare.els10_arm64.deb
    sha:9c189ebd568daded544b88abbbc5878f1f60f59b
  • redis7-tools_7.0.15-1~trixie+tuxcare.els10_arm64.deb
    sha:fc20a85272757fe47344e75bff76688d3fce09f9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.