SUSE-SU-2026:2097-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20262097-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2097-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:2097-1
Upstream
CVE (2)
Related
Published
2026-05-27T14:20:47Z
Modified
2026-05-28T08:15:06Z
Summary
Security update for redis7
Details

This update for redis7 fixes the following issues

  • CVE-2026-23631: Lua use-after-free via the master-replica synchronization mechanism may lead to remote code execution (bsc#1264165).
  • CVE-2026-25243: invalid memory access in RESTORE command via a specially crafted serialized payload may lead to remote code execution (bsc#1264166).

Other updates:

  • an user can manipulate data read by a connection by injecting sequences into a Redis error reply (bsc#1258706).
References

Affected packages