{"id":"openSUSE-SU-2026:21612-1","summary":"Security update for redis","details":"This update for redis fixes the following issues:\n\nChanges in redis:\n\n- Update to 8.10.1\n\n  Update urgency: SECURITY: There are security fixes in the release.\n\n  - Security fixes\n    - (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB\n      loading may lead to heap OOB write\n    - Out-of-bounds access in TopK heap cleanup path (MOD-15410)\n    - Use-after-free in the TLS pending-data list when a command\n      closes another pending connection\n    - A malicious RDB payload with an out-of-range SLOT_INFO slot\n      id causes memory corruption during RDB loading, which may\n      lead to Remote Code Execution\n    - Vector Sets: missing node level validation when loading a\n      vector set from RDB may lead to out-of-bounds access\n    - Vector Sets: use-after-free when VREM mutates the HNSW graph\n      while background VSIM threads are still running\n    - Vector Sets: a negative hnsw_search() return was treated as a\n      huge unsigned count, reading past the end of the result\n      arrays\n    - TLS client certificate authentication bypass: a Common Name\n      containing an embedded NUL byte was truncated, allowing a\n      client to authenticate as another (possibly privileged) ACL\n      user\n    - #15594 Use-after-free in the blocked-client list when\n      reprocessing a command evicts another client blocked on the\n      same key\n\n- Restrict the \"modules\" flavour to x86_64 and aarch64 -- RedisBloom and\n  RedisTimeSeries abort on anything else with \"only supports 64-bit\n  architectures (x64, arm64v8)\", redisjson's vendored redis-module is\n  64-bit only, and modules/common.mk maps no other architecture at all\n\n- Update to 8.10.0\n\n  Major changes compared to 8.8\n  - Compact hashes - a new hash encoding that reduces memory usage\n    by storing hash field names just once for keys that share a\n    schema\n  - New command: HIMPORT - high-throughput compact hash bulk\n    insertion\n  - TLS peer certificate-based server-to-server authentication\n  - New commands: LMOVEM, BLMOVEM - move multiple elements between\n    lists\n  - New command: SUNIONCARD - get the cardinality of the union of\n    multiple sets\n  - New command: SDIFFCARD - get the cardinality of the difference\n    between sets\n  - New command: BACKUP - node-side implementation for backup and\n    restore based on multi-part AOF (MP-AOF)\n  - XREAD, XREADGROUP - new MAXCOUNT and MAXSIZE arguments to cap\n    the cumulative reply entries and size\n  - New command: FT.ALIASLIST - get all aliases for the index\n  - Stemmer support for Malay and Tagalog languages\n  - JSONPath extensions\n  - New commands: TS.NRANGE, TS.NREVRANGE - Query a range across\n    multiple time series; group results by timestamp\n  - New command: TS.READ - optionally blocking read\n  - New command: TS.QUERYLABELS - Get a list of labels and\n    label-values\n  - New command: TS.MRANGE, TS.MREVRANGE - new EXCLUDEEMPTY\n    argument to exclude series with no reported samples\n  - Performance improvements\n\n- Update to 8.8.1\n  Security fixes\n  - RedisBloom/RedisBloom#1044 Crafted RESTORE payloads in\n    RedisBloom and TDigest may trigger out-of-bounds writes,\n    potentially leading to remote code execution\n\n- Update to 8.8.0\n  - New data structure: Array (@antirez)\n  - Subkey notification for hash fields - field-level notifications\n  - INCREX: a window counter rate limiter combining INCR, INCRBY,\n    INCRBYFLOAT, bounds, and expiration (@raffertyyu + Redis team)\n  - XNACK: a new streams command - allow consumers to explicitly\n    release pending messages\n  - ZUNION, ZINTER, ZUNIONSTORE, ZINTERSTORE: new COUNT aggregator\n  - JSON.SET: new FPHA argument to specify the FP type for\n    homogeneous FP arrays\n  - TS.RANGE, TS.REVRANGE, TS.MRANGE, TS.MREVRANGE: multiple\n    aggregators in a single command\n  - FT.HYBRID KNN clause: new argument to request fewer candidates\n    per shard\n  - FT.PROFILE HYBRID: profiling support for FT.HYBRID\n  - Performance improvements\n\n- Updated to 8.6.3 (boo#1264164 boo#1264165 boo#1264166 boo#1264167 boo#1264168)\n  - Security fixes\n    - (CVE-2026-23479) Use-After-Free in unblock client flow may\n      lead to Remote Code Execution.\n    - (CVE-2026-25243) Invalid memory access in RESTORE may lead to\n      Remote Code Execution\n    - (CVE-2026-23631) Lua Use-After-Free may lead to remote code\n      execution\n    - (CVE-2026-25588) Invalid memory access in RESTORE may lead to\n      Remote Code Execution (Time Series)\n    - (CVE-2026-25589) Invalid memory access in RESTORE may lead to\n      Remote Code Execution (Probabilistic)\n  - Bug fixes\n    - SUBSCRIBE, PSUBSCRIBE, SSUBSCRIBE: crash on OOM (RED-167788)\n    - CONFIG SET: some settings allow invalid characters\n      (RED-167787)\n    - SCRIPT DEBUG: potential crash on scripts (RED-175507)\n    - VADD: crash or buffer overflow on large REDUCE value\n      (RED-170921)\n    - VSET: crash on huge allocations (MOD-12678)\n    - Potential crash on disconnections and TLS failures (Time\n      Series) (MOD-14850)\n    - RediSearch/RediSearch#8745 Crash when many keys receive\n      expirations under heavy TTL activity (MOD-14500)\n    - RediSearch/RediSearch#8848 HNSW vector index memory growth\n      under high-churn workloads until shard restart (MOD-13761)\n    - RediSearch/RediSearch#8205, RediSearch/RediSearch#8259\n      FT.HYBRID VSIM RANGE + FILTER incorrectly returns zero\n      results (MOD-12370, MOD-13884)\n    - RediSearch/RediSearch#9182 FT.PROFILE HYBRID returns an empty\n      reply (MOD-14778)\n    - RediSearch/RediSearch#8129, RediSearch/RediSearch#8140\n      FT.PROFILE reports an incorrect shard total profile time\n      (MOD-13735, MOD-13181)\n    - RediSearch/RediSearch#9047 FT.PROFILE output is inconsistent\n      when a profiled value is missing (MOD-10560)\n    - RediSearch/RediSearch#8791 FT.EXPLAIN does not lock, causing\n      a race with concurrent index changes (MOD-14461)\n    - RediSearch/RediSearch#8382 Crash when indexing negative zero\n      (-0.0) (MOD-13904)\n    - RediSearch/RediSearch#8590 FILTER returns inconsistent\n      results with multiple indexes sharing field aliases\n      (MOD-14063)\n    - RediSearch/RediSearch#8660 FILTER behavior depends on\n      property order in the expression (MOD-14065)\n    - RediSearch/RediSearch#8593 Filter expressions are evaluated\n      for indexes that do not match the document type (MOD-14064)\n    - RediSearch/RediSearch#8591 Documents are inconsistently\n      included or excluded depending on the indexing path taken\n      (MOD-13948)\n    - RediSearch/RediSearch#8589 RENAME notification handler loads\n      the wrong key, causing stale index entries after a rename\n      (MOD-14328)\n    - RediSearch/RediSearch#9012 PERSIST and HPERSIST notifications\n      are not reflected in index expiration tracking (MOD-14800)\n    - RediSearch/RediSearch#9079 FT.SPELLCHECK treats PARAMS\n      placeholders as literal terms instead of resolving them\n      (MOD-10596)\n    - RediSearch/RediSearch#8462 GC out-of-memory on replica shards\n      leaves the replica in an inconsistent state (MOD-14066)\n    - RediSearch/RediSearch#9066 Race condition in FT.HYBRID causes\n      intermittent failures under concurrent hybrid query load\n      (MOD-14732)\n    - RediSearch/RediSearch#8109, RediSearch/RediSearch#8149\n      Configuration registration omits module parameters, causing\n      them to be unexposed or misapplied (RED-171841)\n    - RediSearch/RediSearch#9163 Crash on FT.SEARCH when topology\n      validation fails (for example, some nodes unreachable)\n      (MOD-14475)\n    - RediSearch/RediSearch#8395 FT.SEARCH fails with \"Query\n      requires unavailable slots\" after shard restart or failover\n      (MOD-13828)\n    - RediSearch/RediSearch#8451 FT.INFO-style output no longer\n      reports zero-index summary data when no indices exist\n      (MOD-14079)\n    - RediSearch/RediSearch#9078 FT.CREATE now rejects schema\n      definitions with invalid option combinations at creation time\n      (MOD-14655)\n    - RediSearch/RediSearch#8051, RediSearch/RediSearch#8114 Crash\n      diagnostics now include the IndexSpec of the index the\n      failing thread was working on (MOD-7574)\n  - Metrics\n    - RediSearch/RediSearch#8210, RediSearch/RediSearch#8231\n      FT.PROFILE: added queue time tracking (MOD-13602)\n\n- Updated to 8.6.2 (boo#1260399)\n  * Fixed potential UAF: don't use reply copy avoidance for module strings.\n  * Fixed crash during command processing on replicas performing.\n    full synchronization.\n  * Fixed potential Memory leaks.\n  * Fixed potential crash during ACL checks on wrong-arity commands.\n  * Fixed HSETEX HGETEX do not validate that FIELDS is specified only once.\n\n- Updated to 8.6.1 (boo#1258706)\n  * Fixed user can manipulate data read by a connection by\n    injecting \\r\\n sequences into a Redis error reply.\n  * Fixed INFO command may display module information,\n    and the missing HOTKEYS HELP subcommand has been added.\n  * Fixed RDB loading prevented hash table expansion.\n\n- Updated to 8.6.0\n\n  Major changes compared to 8.4\n  - Substantial performance improvements\n  - Substantial memory reduction for hashes (hashtable-encoded) and\n    sorted sets (skiplist-encoded)\n  - Streams: XADD idempotency (at-most-once guarantee) with new\n    IDMPAUTO and IDMP arguments\n  - New eviction policies - least recently modified: volatile-lrm\n    and allkeys-lrm\n  - Hot keys detection and reporting; new command: HOTKEYS\n  - TLS certificate-based automatic client authentication\n  - Time series: support NaN values; new aggregators: COUNTNAN and\n    COUNTALL\n\n  New Features\n  - #14695 Keys memory size histograms\n  - #14615 Streams: XADD idempotency (at-most-once guarantee) with\n    new IDMPAUTO and IDMP arguments\n  - #14624 New eviction policies - least recently modified:\n    volatile-lrm and allkeys-lrm\n  - #14680 Hot keys detection and reporting; new command: HOTKEYS\n  - #14610 TLS certificate-based automatic client authentication\n  - RedisTimeSeries/RedisTimeSeries#1853 Time series: support NaN\n    values; new aggregators: COUNTNAN and COUNTALL Security and\n    privacy fixes\n  - #14645 Hide Personally Identifiable Information from ACL log\n  - #14659 ACL: Key-pattern bypass in MSETEX\n  - RedisTimeSeries/RedisTimeSeries#1837, RedisJSON/RedisJSON#1474\n    Hide Personally Identifiable Information from server log\n  - RedisBloom/RedisBloom#950 Out-of-bounds read when loading an\n    invalid RDB file (MOD-12802) Bugfixes\n  - #14545 ACL: AOF loading fails if ACL rules are changed and\n    don't allow some commands in MULTI-EXEC\n  - #14637 Atomic slot migration: wrong adjacent slot range\n    behavior\n  - #14567 Atomic slot migration: support delay trimming slots\n    after finishing migrating slots\n  - #14623 Streams: XTRIM/XADD with approx mode (~) don’t delete\n    entries for DELREF/ACKED strategies\n  - #14552 Streams: Incorrect behavior when using\n    XDELEX...ACKEDafterXGROUP DESTROY`\n  - #14537 SCAN: restore original filter order (revert change\n    introduced in 8.2)\n  - #14581 Rare server hang at shutdown\n  - #14597 Panic when cluster node is uninitialized\n  - #14583 FLUSHALL ASYNC on a writable replica may block the main\n    thread for an extended period\n  - #14504 Cluster: fix race condition in broadcast configuration\n  - #14416 Fixed argument position handling in Redis APIs\n  - RedisTimeSeries/RedisTimeSeries#1784,\n    RedisTimeSeries/RedisTimeSeries#1839,\n    RedisBloom/RedisBloom#952, RedisJSON/RedisJSON#1477 Atomic slot\n    migration support\n  - RedisBloom/RedisBloom#946 MEMORY USAGE: fix reported value\n    (MOD-12799)\n  - RedisJSON/RedisJSON#1473 Adding escapes to already-escaped\n    characters (MOD-8137)\n  - RedisJSON/RedisJSON#1475 JSON.CLEAR does not error if more than\n    one path is specified (MOD-13109) Performance and resource\n    utilization improvements\n  - #14608 Reply copy-avoidance path to reduce memory copies for\n    bulk string replies\n  - #14595 Hash: unify field name and value into a single struct\n  - #14701 Sorted set: unify score and value into a single struct\n  - #14662 Optimize listpack iterator on hash fields\n  - #14699 Optimize set commands with expiration\n  - #14700 Optimize prefetching\n  - #14715 Optimize prefetch sizing logic\n  - #14636 Optimize ZRANK\n  - #14676 Utilize hardware clock by default on ARM AArch64\n  - #14575 Disable RDB compression when diskless replication is\n    used\n  - #14714 Optimize user ACL permission verification\n  - #14692 Optimize peak memory metric collection\n  - #14739 Avoid allocating and releasing list node in reply copy\n    avoidance\n  - #14713 Reduce per command syscalls by reusing cached time when\n    hardware monotonic clock is available\n  - #14726 Optimize XREADGROUP CLAIM\n  - #13962 Vector set: replace manual popcount with\n    __builtin_popcountll for binary vector distance (Intel, AMD,\n    ARM)\n  - #14474 Vector set: vectorized the quantized 8-bit vector\n    distance calculation (Intel, AMD)\n  - #14492 Vector set: vectorize binary quantization path for\n    vectorsets distance calculation (Intel, AMD) Configuration\n    parameters\n  - #14719 cluster-slot-stats-enabled - per-slot resource\n    consumptions statistics to collect\n  - #14695 key-memory-histograms collect memory consumption\n    histograms per data type Metrics\n  - #14695 db0_distrib_lists_sizes, db0_distrib_sets_sizes,\n    db0_distrib_hashes_sizes, db0_distrib_zsets_sizes\n  - #14610 acl_access_denied_tls_cert - failed TLS\n    certificate–based authentication attempts Modules API\n  - #14445\n    - RM_CreateKeyMetaClass - define a new key-metadata class\n    - RM_ReleaseKeyMetaClass - release a key-metadata class\n    - RM_SetKeyMeta - attach or update a metadata value for a key\n      under a specific metadata-key class\n    - RM_GetKeyMeta - get a metadata value for a key under a\n      specific metadata-key class Configuration parameters\n  - #14624 maxmemory-policy: new eviction policies: volatile-lrm,\n    allkeys-lrm\n  - #14615 stream-idmp-duration, stream-idmp-maxsize - defaults for\n    streams idempotent production\n  - #14610 tls-auth-clients-user TLS certificate-based automatic\n    client authentication\n  - #14596 flushdb option for repl-diskless-load: always flush the\n    entire dataset before diskless load Known bugs and limitations\n  - Streams: avoid using XADD with the new IDMP or IDMPAUTO options\n    when using appendonly yes with aof-use-rdb-preamble no (non\n    default). This limitation will be removed in the next patch.\n  - Redis Query Engine: In case of load rebalancing operations\n    (such as Atomic Slot Migration) taking place during the\n    lifetime of a cursor, there is a chance that some results may\n    be missing.\n\n- Updated to 8.4.1\n  * https://github.com/redis/redis/releases/tag/8.4.1\n  * Atomic slot migration: wrong adjacent slot range behavior.\n  * Atomic slot migration: support delay trimming slots after\n    finishing migrating slots.\n  * Fixed CLUSTER SLOT-STATS few memory tracking bugs.\n\n- Updated to 8.4.0\n  - Major changes compared to 8.2\n    - DIGEST, DELEX; SET extensions - atomic compare-and-set and\n      compare-and-delete for string keys\n    - MSETEX - atomically set multiple string keys and update their\n      expiration\n    - XREADGROUP - new CLAIM option for reading both idle pending\n      and incoming stream entries\n    - CLUSTER MIGRATION - atomic slot migration\n    - CLUSTER SLOT-STATS - per-slot usage metrics: key count, CPU\n      time, and network I/O\n    - Redis query engine: FT.HYBRID - hybrid search and fused\n      scoring\n    - Redis query engine: I/O threading with performance boost for\n      search and query commands (FT.*)\n    - I/O threading: substantial throughput increase (e.g. \u003e30% for\n      caching use cases (10% SET, 90% GET), 4 cores)\n    - JSON: substantial memory reduction for homogenous arrays (up\n      to 91%)\n","modified":"2026-08-23T18:23:30.468612056Z","published":"2026-08-20T14:41:12Z","related":["CVE-2026-23479","CVE-2026-23631","CVE-2026-25243","CVE-2026-25588","CVE-2026-25589","CVE-2026-62356"],"upstream":["CVE-2026-23479","CVE-2026-23631","CVE-2026-25243","CVE-2026-25588","CVE-2026-25589","CVE-2026-62356"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258706"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260399"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264164"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264165"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264166"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264167"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264168"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23479"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23631"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25243"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25588"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25589"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-62356"}],"affected":[{"package":{"name":"redis","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/redis&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.10.1-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"redis-bloom":"8.10.1-bp160.1.1","redis-json":"8.10.1-bp160.1.1","redis-search":"8.10.1-bp160.1.1","redis-timeseries":"8.10.1-bp160.1.1","redis":"8.10.1-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21612-1.json"}},{"package":{"name":"redis-modules","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/redis-modules&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.10.1-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"redis-bloom":"8.10.1-bp160.1.1","redis-json":"8.10.1-bp160.1.1","redis-search":"8.10.1-bp160.1.1","redis-timeseries":"8.10.1-bp160.1.1","redis":"8.10.1-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21612-1.json"}}],"schema_version":"1.9.0"}