ELA-1795-1 redis security update

remote-code execution vulnerability

2026-08-06
Packageredis
Version5:5.0.14-1+deb10u11 (buster)
Related CVEs CVE-2026-66373


Fix a potential remote-code execution vulnerability in Redis, the key-value database.

In the unusual case where an authenticated attacker could execute the RESTORE command, a malicious RESTORE payload could have resulted in a double-free.



For Debian 10 buster, these problems have been fixed in version 5:5.0.14-1+deb10u11.

We recommend that you upgrade your redis packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.