Debian Patches
Status for redis/5:7.0.15-1~deb12u10
| Patch | Description | Author | Forwarded | Bugs | Origin | Last update |
|---|---|---|---|---|---|---|
| debian-packaging/0001-Set-Debian-configuration-defaults.patch | Set Debian configuration defaults | Chris Lamb <lamby@debian.org> | not-needed | 2017-10-10 | ||
| 0001-Fix-FTBFS-on-kFreeBSD.patch | Fix FTBFS on kFreeBSD | Chris Lamb <lamby@debian.org> | no | 2015-10-30 | ||
| 0002-Add-CPPFLAGS-to-upstream-makefiles.patch | Add CPPFLAGS to upstream makefiles | Chris Lamb <lamby@debian.org> | no | 2015-10-30 | ||
| 0003-Use-get_current_dir_name-over-PATHMAX.patch | Use get_current_dir_name over PATHMAX, etc. | Chris Lamb <lamby@debian.org> | no | 2018-01-24 | ||
| 0004-Add-support-for-USE_SYSTEM_JEMALLOC-flag.patch | Add support for USE_SYSTEM_JEMALLOC flag. | Chris Lamb <lamby@debian.org> | yes | 2018-08-25 | ||
| 0001-Apply-security-fixes-for-CVEs-1113.patch | Apply security fixes for CVEs (#1113) Apply the security fixes for the release. (CVE-2024-31449) Lua library commands may lead to stack overflow and potential RCE. (CVE-2024-31227) Potential Denial-of-service due to malformed ACL selectors. (CVE-2024-31228) Potential Denial-of-service due to unbounded pattern matching. |
Madelyn Olson <madelyneolson@gmail.com> | no | 2024-10-02 | ||
| 0001-Fix-LUA-garbage-collector-CVE-2024-46981-1513.patch | Fix LUA garbage collector (CVE-2024-46981) (#1513) Reset GC state before closing the lua VM to prevent user data to be wrongly freed while still might be used on destructor callbacks. Created and publish by Redis in their OSS branch. |
Madelyn Olson <madelyneolson@gmail.com> | no | 2025-01-06 | ||
| 0002-Fix-Read-Write-key-pattern-selector-CVE-2024-51741-1.patch | Fix Read/Write key pattern selector (CVE-2024-51741) (#1514) The explanation on the original commit was wrong. Key based access must have a `~` in order to correctly configure whey key prefixes to apply the selector to. If this is missing, a server assert will be triggered later. |
Madelyn Olson <madelyneolson@gmail.com> | no | 2025-01-06 | ||
| 0001-Limiting-output-buffer-for-unauthenticated-client-CV.patch | Limiting output buffer for unauthenticated client (CVE-2025-21605) For unauthenticated clients the output buffer is limited to prevent them from abusing it by not reading the replies |
YaacovHazan <yaacov.hazan@redis.com> | no | 2025-04-23 | ||
| 0005-CVE-2025-27151.patch | Check length of AOF file name in redis-check-aof (CVE-2025-27151) Ensure that the length of the input file name does not exceed PATH_MAX |
YaacovHazan <yaacov.hazan@redis.com> | no | 2025-05-27 | ||
| 0006-CVE-2025-32023.patch | Fix out of bounds write in hyperloglog commands (CVE-2025-32023) | "debing.sun" <debing.sun@redis.com> | no | 2025-05-07 | ||
| 0007-CVE-2025-48367.patch | Retry accept() even if accepted connection reports an error (CVE-2025-48367) In case of accept4() returns an error, we should check errno value and decide if we should retry accept4() without waiting next event loop iteration. |
Ozan Tezcan <ozantezcan@gmail.com> | no | 2025-05-14 | ||
| CVE-2025-46817.patch | Lua script may lead to integer overflow and potential RCE (CVE-2025-46817) | Ozan Tezcan <ozantezcan@gmail.com> | no | 2025-06-23 | ||
| CVE-2025-46818.patch | Lua script can be executed in the context of another user (CVE-2025-46818) | Ozan Tezcan <ozantezcan@gmail.com> | no | 2025-06-23 | ||
| CVE-2025-49844.patch | Lua script may lead to remote code execution (CVE-2025-49844) | Mincho Paskalev <minchopaskal@gmail.com> | no | 2025-06-23 | ||
| CVE-2025-46819.patch | LUA out-of-bound read (CVE-2025-46819) | Ozan Tezcan <ozantezcan@gmail.com> | no | 2025-06-23 | ||
| CVE-2025-67733.patch | Strip CRLF from error and simple string replies (#826) Because in some cases, the client put \r\n in the command parameters. When Redis returns these parameters to the client via an error reply, the presence of \r\n in the middle can cause the client to only parse the portion before the \r\n when handling the error reply. This disrupts the protocol parsing and ultimately causes the connection to become stuck. [Backport from https://github.com/redis/redis/commit/6910256443c74057e0d83e08c61ea0021774fa6f] [Adapted for redis-7.0.15: - redis-7.0.15 already has addReplyErrorSdsSafe(); only the new addReplyErrorSdsExSafe() and addReplyStatusSafe() helpers are added. - functions.c hunk uses the pre-existing addReplyErrorSdsSafe(). - tests/unit/functions.tcl test added inside the same start_server block, before its closing brace. - tests/unit/moduleapi/reply.tcl test added inside the proto loop, before its closing brace (7.0.15 lacks the upstream "WRONGTYPE A type error" anchor). - tests/unit/scripting.tcl test added before "LUA redis.status_reply API" anchor.] |
"debing.sun" <debing.sun@redis.com> | no | 2025-12-28 | ||
| CVE-2026-21863.patch | Fix for [CVE-2026-21863] Remote DoS with malformed Valkey Cluster bus message [Backport from Valkey commit https://github.com/valkey-io/valkey/commit/416939303d2550aefff73ac180f41b84c12ba6c0] [Adapted for redis-7.0.15: - redis-7.0.15 has src/cluster.c (not src/cluster_legacy.c). - The enclosing function is clusterProcessPacket() (not clusterIsValidPacket()). - Drop/keep-link return value is 1 (not 0) on redis-7.0.15. - extlen is uint16_t (not uint32_t) on redis-7.0.15; only the two new bounds-check blocks from upstream are inserted; existing declarations are unchanged. - tests/unit/cluster/packet.tcl is included verbatim; the file is not auto-registered in tests/test_helper.tcl since the upstream Valkey patch does not register it either. start_cluster, CI, R helpers used by the test all exist in redis-7.0.15.] |
Roshan Khatri <rvkhatri@amazon.com> | no | 2026-02-23 | ||
| CVE-2026-23631.patch | Fix use-after-free when fullsync happens while replica is running a timed out script (CVE-2026-23631) Fullsync triggers emptyData and scriptingReset which free the scripting/function engine. If a timed out script is still running on the replica, this causes a use-after-free. Delay fullsync processing in readSyncBulkPayload until the script finishes. |
Ozan Tezcan <ozantezcan@gmail.com> | no | upstream, https://github.com/redis/redis/commit/0cca172a174642bdae03b871615227896274d9bb.patch | 2026-04-14 | |
| CVE-2026-25243.patch | Invalid Memory Access in Redis RESTORE Command (CVE-2026-25243) | Sergei Georgiev <s_ggeorgiev@yahoo.com> | no | upstream, https://github.com/redis/redis/commit/b9dde6fc25dec6191b18374335a076a7b31e3d02.patch | 2025-11-27 | |
| CVE-2026-66373.patch | Reject corrupt stream RDB with shared NACK across consumers (#15081) **Summary** Detects and rejects corrupt stream RDB payloads where the same NACK (pending entry) is referenced by more than one consumer, which violates a stream data-structure. **Changes** - **`rdbLoadObject` (stream consumer PEL loading)**: Added a guard that checks `nack->consumer != NULL` before assigning the consumer pointer. When a second consumer's PEL references a NACK that was already claimed by a prior consumer, the loader now reports a corrupt RDB error and aborts instead of silently overwriting the pointer. Without this check, two consumers share the same `streamNACK`, and freeing the first consumer's PEL leaves the second with a dangling pointer. - **`corrupt-dump.tcl`**: Added a regression test that crafts a stream with two consumers (`consumerA`, `consumerB`) whose PELs both reference the same entry (`1-0`). The `RESTORE` command is expected to fail with `"Bad data format"`, and the server must remain responsive (`PING` succeeds). **Benefits** - **Fail-fast on corrupt data**: The invariant violation is caught at load time with a clear diagnostic message rather than manifesting as a crash later during normal operation. - **Regression coverage**: The crafted payload in the test ensures this class of corruption is permanently guarded against. |
sggeorgiev <s_ggeorgiev@yahoo.com> | no | upstream, https://github.com/redis/redis/commit/41a958720e64e03576dd652d224aa46d22c096c3.patch | 2026-04-23 | |
| CVE-2026-81934.patch | Fix use-after-free in tlsProcessPendingData() pending-list iteration (#1391) `tlsProcessPendingData()` iterates `pending_list` using a `listIter`, which pre-caches the `next` node pointer on every `listNext()` call. This cached pointer can dangle and be dereferenced after the node it points to has been freed, causing a use-after-free and a server crash (SIGSEGV). The issue occurs because `tlsHandleEvent()` runs the connection's read handler, which can execute a command (e.g. `CLIENT KILL`) that closes a *different* pending TLS connection. That close path goes through `freeClient()` → `connClose()` → `connTLSClose()`, which calls `listDelNode()` and frees the victim connection's `pending_list` node. If the iterator's cached `next` pointer referenced that node, the following `listNext()` reads freed memory. The `listNext()` contract only permits removing the *current* node, not arbitrary other nodes. Replace the `listIter`-based iteration with a detach-from-head, bounded drain so that no list node pointer is ever held across a handler call: - Re-read `listFirst()` on each iteration instead of relying on a pre-cached `next` pointer - Detach the head via `tlsPendingRemove()` *before* calling `tlsHandleEvent()`, so the loop always makes forward progress - Semantics are preserved: in the common case each connection is handled exactly once per cycle, in order (cherry picked from commit 98ff29b2828bf3245167b416ee23e6797f551a37) |
Sergei Georgiev <s_ggeorgiev@yahoo.com> | no | upstream, https://github.com/redis/redis/commit/6d088c335d5c3ec49a6c28486140b498e70b7834.patch | 2026-06-09 | |
| CVE-2026-92925.patch | Reject cluster bus PING extensions with missing null terminator (#15263) The cluster bus PING/PONG/MEET packet parser validated extension padding and total length but never checked that string-carrying extensions are properly null-terminated, allowing a crafted packet to trigger out-of-bounds reads when the payload is later consumed as a C string. 1. **Null-termination check for hostname and human-nodename extensions (`cluster_legacy.c`)** Added a check inside the existing extension-validation loop in `clusterProcessPacket`: for `CLUSTERMSG_EXT_TYPE_HOSTNAME` and `CLUSTERMSG_EXT_TYPE_HUMAN_NODENAME` extension types, it verifies that the data portion is non-empty (`datalen > 0`) and that the last byte is `''`. Packets failing this check are rejected with a warning log and an early return, the same way other malformed-extension cases are handled. 2. **Test (`hostnames.tcl`)** A new test exercises the rejection path by constructing a raw cluster-bus PING packet with a 32-byte hostname extension that contains no `''`, sending it directly to a node's bus port, and verifying the packet is dropped (warning logged, hostname not updated in `CLUSTER NODES`). Two helper procs (`build_cluster_bus_ping` and `build_hostname_extension`) build the binary packet from scratch in Tcl, allowing fine-grained control over extension contents without needing a modified Redis sender. |
Sergei Georgiev <s_ggeorgiev@yahoo.com> | no | upstream, https://github.com/redis/redis/commit/37894faeea11e2db28b9fc2af378a762d2c36523.patch | 2026-06-05 |
All known versions for source package 'redis'
- 5:8.6.3-1 (experimental)
- 5:8.0.6-3 (forky, sid)
- 5:8.0.2-3+deb13u2 (trixie-security, trixie)
- 5:7.0.15-1~deb12u10 (bookworm-security)
- 5:7.0.15-1~deb12u7 (bookworm)
