[CLSA-2026:1789388743] Fix CVE(s): CVE-2026-81934
Type:
security
Severity:
Important
Release date:
2026-09-14 12:25:54 UTC
Description:
* SECURITY UPDATE: Use-after-free in TLS pending-data processing - debian/patches/CVE-2026-81934.patch: drain the TLS pending list from its head and detach each node before running its event handler in src/tls.c, so a handler that closes another pending connection cannot leave the iterator holding a freed node - CVE-2026-81934
CVEs fixed:
Updated packages:
  • redis_6.0.16-1+deb11u9+tuxcare.els2_all.deb
    sha:778d8d6df3c93aa017707bde7e5be584b14a4a18
  • redis-sentinel_6.0.16-1+deb11u9+tuxcare.els2_amd64.deb
    sha:6cc56a29317eada94d7f29dcc7dbce5ea0596d45
  • redis-server_6.0.16-1+deb11u9+tuxcare.els2_amd64.deb
    sha:56f3edd60e2cfc922e508da8c50401d60f9c7ae8
  • redis-tools_6.0.16-1+deb11u9+tuxcare.els2_amd64.deb
    sha:32488b92d8dced8537d9fa199a8115eedfca2550
  • redis-sentinel_6.0.16-1+deb11u9+tuxcare.els2_arm64.deb
    sha:718af1443db903c1dcc9d4017d081930e51210fb
  • redis-server_6.0.16-1+deb11u9+tuxcare.els2_arm64.deb
    sha:381647e3c2495a91ea70ed619abef8786dc79ef2
  • redis-tools_6.0.16-1+deb11u9+tuxcare.els2_arm64.deb
    sha:3a4b6c3698cc855f2c5b34787cbecbb57ee431a0
  • redis-sentinel_6.0.16-1+deb11u9+tuxcare.els2_armel.deb
    sha:fbf254742401fef043171037712220033909c471
  • redis-server_6.0.16-1+deb11u9+tuxcare.els2_armel.deb
    sha:a402f0fee74c7e4dfa134c6f64a4972941ea4cc4
  • redis-tools_6.0.16-1+deb11u9+tuxcare.els2_armel.deb
    sha:fe43b694b0e6682cd0e4115efce217f40d000f11
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.