{"id":"SUSE-SU-2026:2099-1","summary":"Security update for redis","details":"This update for redis fixes the following issues\n\n- CVE-2026-23479: use-after-free in unblock client flow may lead to remote code execution (bsc#1264164).\n- CVE-2026-23631: Lua use-after-free via the master-replica synchronization mechanism may lead to remote code execution\n  (bsc#1264165).\n- CVE-2026-25243: invalid memory access in RESTORE command via a specially crafted serialized payload may lead to remote\n  code execution (bsc#1264166).\n","modified":"2026-05-28T08:15:05.375876247Z","published":"2026-05-27T14:21:52Z","related":["CVE-2026-23479","CVE-2026-23631","CVE-2026-25243"],"upstream":["CVE-2026-23479","CVE-2026-23631","CVE-2026-25243"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20262099-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264164"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264165"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264166"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23479"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23631"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25243"}],"schema_version":"1.7.5"}