[CLSA-2026:1784617268] Fix CVE(s): CVE-2025-49112
Type:
security
Severity:
Low
Release date:
2026-07-21 07:01:33 UTC
Description:
* SECURITY UPDATE: Integer underflow in setDeferredReply leads to out-of-bounds write via crafted client output buffer - debian/patches/CVE-2025-49112.patch: replace the unsigned subtraction check prev->size - prev->used > 0 with prev->used < prev->size in setDeferredReply to avoid underflow when prev->used exceeds prev->size - CVE-2025-49112
CVEs fixed:
Updated packages:
  • redis6.2_6.2.21-1~bookworm+tuxcare.els6_all.deb
    sha:ff405fb29661e19d01a76214c60af64471c06f42
  • redis6.2-sentinel_6.2.21-1~bookworm+tuxcare.els6_amd64.deb
    sha:ae066b70eab0c1c4ae9994d8086d107893b46c9c
  • redis6.2-server_6.2.21-1~bookworm+tuxcare.els6_amd64.deb
    sha:c9b4040c2b65862dd8cb49ad281f05f33f884e4f
  • redis6.2-tools_6.2.21-1~bookworm+tuxcare.els6_amd64.deb
    sha:7b2dd8cb06b6dc564a2fcd9b5c940bc9a4c22cec
  • redis6.2_6.2.21-1~bookworm+tuxcare.els6_all.deb
    sha:ff405fb29661e19d01a76214c60af64471c06f42
  • redis6.2-sentinel_6.2.21-1~bookworm+tuxcare.els6_arm64.deb
    sha:c9b1a248be65a0d48effba0b1b7e0285b5c1e0a9
  • redis6.2-server_6.2.21-1~bookworm+tuxcare.els6_arm64.deb
    sha:8f2534a2af58c41af1355fa6f185da2e78c4d380
  • redis6.2-tools_6.2.21-1~bookworm+tuxcare.els6_arm64.deb
    sha:84900f235818b0d5f225a19aa63f790a21aab678
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.