ELA-1831-1 redis security update

use-after-free vulnerability

2026-09-24
Packageredis
Version5:6.0.16-1+deb11u10 (bullseye)
Related CVEs CVE-2026-81934


A use-after-free vulnerability was discovered in the Redis key/value database in the handling of pending TLS data. A remote, unauthenticated attacker may be been able to execute arbitrary commands with the privileges of the Redis server.



For Debian 11 bullseye, these problems have been fixed in version 5:6.0.16-1+deb11u10.

We recommend that you upgrade your redis packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.