stable

redis-7.0.13-1.fc38

FEDORA-2023-03422cb8de created by remi a year ago for Fedora 38

Redis 7.0.13 Released Wed 06 Sep 2023 15:00:00 IDT

Upgrade urgency SECURITY: See security fixes below.

Security Fixes

  • (CVE-2023-41053) Redis does not correctly identify keys accessed by SORT_RO and as a result may grant users executing this command access to keys that are not explicitly authorized by the ACL configuration.

Bug Fixes

  • Cluster: fix a race condition where a slot migration may revert on a subsequent failover or node joining (#12344)
  • Ensure that the function load timeout is disabled during loading from RDB/AOF and on replicas. (#12451)
  • Fix the assertion when script timeout occurs after it signaled a blocked client (#12459)

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2023-03422cb8de

This update has been submitted for testing by remi.

a year ago

This update's test gating status has been changed to 'ignored'.

a year ago

This update has been pushed to testing.

a year ago
User Icon frantisekz provided feedback a year ago
karma

remi edited this update.

a year ago

This update has been submitted for stable by bodhi.

a year ago

This update has been pushed to stable.

a year ago

Please login to add feedback.

Metadata
Type
security
Severity
medium
Karma
1
Signed
Content Type
RPM
Test Gating
Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
7 days
Dates
submitted
a year ago
in testing
a year ago
in stable
a year ago
modified
a year ago
approved
a year ago
BZ#2237826 CVE-2023-41053 redis: Redis SORT_RO may bypass ACL configuration
0
0
BZ#2238564 CVE-2023-41053 redis: Redis SORT_RO may bypass ACL configuration [fedora-38]
0
0

Automated Test Results