rpm package
opensuse/redis-modules&distro=openSUSE Leap 16.0
pkg:rpm/opensuse/redis-modules&distro=openSUSE%20Leap%2016.0
Vulnerabilities (5)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-25589 | Hig | 8.8 | < 8.10.1-bp160.1.1 | 8.10.1-bp160.1.1 | May 5, 2026 | RedisBloom is a probabilistic data structures module for Redis. In all versions of RedisBloom before 2.8.20, the module does not properly validate serialized values processed through the Redis RESTORE command. An authenticated attacker with permission to execute RESTORE on a serv | |
| CVE-2026-25588 | Hig | 8.8 | < 8.10.1-bp160.1.1 | 8.10.1-bp160.1.1 | May 5, 2026 | RedisTimeSeries is a time-series module for Redis. In all versions before 1.12.14 of RedisTimeSeries, the module does not properly validate serialized values processed through the Redis RESTORE command. An authenticated attacker with permission to execute RESTORE on a server with | |
| CVE-2026-25243 | Hig | 8.8 | < 8.10.1-bp160.1.1 | 8.10.1-bp160.1.1 | May 5, 2026 | Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker with permission to execute RESTORE can supply a crafted serialized payload that triggers invalid memory | |
| CVE-2026-23631 | Hig | 8.1 | < 8.10.1-bp160.1.1 | 8.10.1-bp160.1.1 | May 5, 2026 | Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled or can be disabled, which | |
| CVE-2026-23479 | Hig | 8.8 | < 8.10.1-bp160.1.1 | 8.10.1-bp160.1.1 | May 5, 2026 | Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated a |
- affected < 8.10.1-bp160.1.1fixed 8.10.1-bp160.1.1
RedisBloom is a probabilistic data structures module for Redis. In all versions of RedisBloom before 2.8.20, the module does not properly validate serialized values processed through the Redis RESTORE command. An authenticated attacker with permission to execute RESTORE on a serv
- affected < 8.10.1-bp160.1.1fixed 8.10.1-bp160.1.1
RedisTimeSeries is a time-series module for Redis. In all versions before 1.12.14 of RedisTimeSeries, the module does not properly validate serialized values processed through the Redis RESTORE command. An authenticated attacker with permission to execute RESTORE on a server with
- affected < 8.10.1-bp160.1.1fixed 8.10.1-bp160.1.1
Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker with permission to execute RESTORE can supply a crafted serialized payload that triggers invalid memory
- affected < 8.10.1-bp160.1.1fixed 8.10.1-bp160.1.1
Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled or can be disabled, which
- affected < 8.10.1-bp160.1.1fixed 8.10.1-bp160.1.1
Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated a