{"id":"SUSE-SU-2021:1652-1","summary":"Security update for redis","details":"This update for redis fixes the following issues:\n\nredis was updated to 6.0.13:\n\n* CVE-2021-29477: Integer overflow in STRALGO LCS command (bsc#1185729)\n* CVE-2021-29478: Integer overflow in COPY command for large intsets (bsc#1185730)\n* Cluster: Skip unnecessary check which may prevent failure detection\n* Fix performance regression in BRPOP on Redis 6.0\n* Fix edge-case when a module client is unblocked\n\nredis 6.0.12:\n\n* Fix compilation error on non-glibc systems if jemalloc is not used\n\nredis 6.0.11:\n\n* CVE-2021-21309: Avoid 32-bit overflows when proto-max-bulk-len\n  is set high (bsc#1182657)\n* Fix handling of threaded IO and CLIENT PAUSE (failover), could\n  lead to data loss or a crash\n* Fix the selection of a random element from large hash tables\n* Fix broken protocol in client tracking tracking-redir-broken message\n* XINFO able to access expired keys on a replica\n* Fix broken protocol in redis-benchmark when used with -a or\n  --dbnum \n* Avoid assertions (on older kernels) when testing arm64 CoW bug\n* CONFIG REWRITE should honor umask settings\n* Fix firstkey,lastkey,step in COMMAND command for some commands\n* RM_ZsetRem: Delete key if empty, the bug could leave empty\n  zset keys \n\n- Switch systemd type of the sentinel service from notify to simple. This can\n  be reverted when updating to 6.2 which fixes\n  https://github.com/redis/redis/issues/7284 .\n","modified":"2026-03-11T07:16:43.356778Z","published":"2021-05-19T12:30:32Z","related":["CVE-2021-21309","CVE-2021-29477","CVE-2021-29478"],"upstream":["CVE-2021-21309","CVE-2021-29477","CVE-2021-29478"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2021/suse-su-20211652-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1182657"},{"type":"REPORT","url":"https://bugzilla.suse.com/1185729"},{"type":"REPORT","url":"https://bugzilla.suse.com/1185730"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-21309"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-29477"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-29478"}],"affected":[{"package":{"name":"redis","ecosystem":"SUSE:Linux Enterprise Module for Server Applications 15 SP2","purl":"pkg:rpm/suse/redis&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.13-1.10.1"}]}],"ecosystem_specific":{"binaries":[{"redis":"6.0.13-1.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:1652-1.json"}},{"package":{"name":"redis","ecosystem":"SUSE:Linux Enterprise Module for Server Applications 15 SP3","purl":"pkg:rpm/suse/redis&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.13-1.10.1"}]}],"ecosystem_specific":{"binaries":[{"redis":"6.0.13-1.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:1652-1.json"}}],"schema_version":"1.7.5"}