Fixed multiple critical security vulnerabilities including CVE‑2026‑62356, heap out‑of‑bounds write, use‑after‑free, and TLS client certificate authentication bypass.
No matching updates in this bucket.
Backend updates in 2026-w34
Fixed several critical CVE‑2026‑62356 vulnerabilities: buffer overflow, out‑of‑bounds access, use‑after‑free, and ACL bypass in commands like SORT, GEORADIUS, and XREADGROUP.
Fixed multiple heap OOB write and use‑after‑free vulnerabilities in CMSketch loading, TopK cleanup, and TLS pending data handling.
Fixed multiple heap and out‑of‑bounds write vulnerabilities (CVE‑2026‑62356) including CMSketch RDB loading and TopK cleanup
Fixed multiple memory corruption vulnerabilities including OOB writes, use‑after‑free, and out‑of‑bounds reads in RDB loading, CMSketch, TopK cleanup, TLS pending data, ACL checks, and vector set handling.
Fixed multiple use‑after‑free vulnerabilities affecting TLS pending data handling and the blocked client list.
Fixed multiple use‑after‑free vulnerabilities in TLS pending data handling and blocked‑client list processing.
Fixed a use‑after‑free vulnerability in TLS pending‑data handling when a command closes another pending connection.