Fedora Security Advisories

valkey-8.0.3-1.el9

5 days 22 hours ago
FEDORA-EPEL-2025-eb3543f6b8 Packages in this update:
  • valkey-8.0.3-1.el9
Update description:

Valkey 8.0.3 - Released Wed 23 Apr 2025

Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.

Bug fixes

  • Optimize RDB load performance and fix cluster mode resizing on replica side (#1199)
  • Fix memory leak in forgotten node ping ext code path (#1574)
  • Fix cluster info sent stats for message with light header (#1563)
  • Fix module LatencyAddSample still work when latency-monitor-threshold is 0 (#1541)
  • Fix potential crash in radix tree recompression of huge keys (#1722)
  • Fix error "SSL routines::bad length" when connTLSWrite is called second time with smaller buffer (#1737)
  • Fix temp file leak druing replication error handling (#1721)
  • Fix ACL LOAD crash on replica since the primary client don't has a user (#1842)
  • Fix RANDOMKEY infinite loop during CLIENT PAUSE (#1850)
  • fix: add samples to stream object consumer trees (#1825)
  • Fix cluster slot stats assertion during promotion of replica (#1950)
  • Fix panic in primary when blocking shutdown after previous block with timeout (#1948)
  • Ignore stale gossip packets that arrive out of order (#1777)
  • Fix incorrect lag reported in XINFO GROUPS (#1952)
  • Avoid shard id update of replica if not matching with primary shard id (#573)

Security fixes

  • CVE-2025-21605 Limit output buffer for unauthenticated clients (#1993)

valkey-8.0.3-1.fc40

5 days 22 hours ago
FEDORA-2025-59ebc165fc Packages in this update:
  • valkey-8.0.3-1.fc40
Update description:

Valkey 8.0.3 - Released Wed 23 Apr 2025

Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.

Bug fixes

  • Optimize RDB load performance and fix cluster mode resizing on replica side (#1199)
  • Fix memory leak in forgotten node ping ext code path (#1574)
  • Fix cluster info sent stats for message with light header (#1563)
  • Fix module LatencyAddSample still work when latency-monitor-threshold is 0 (#1541)
  • Fix potential crash in radix tree recompression of huge keys (#1722)
  • Fix error "SSL routines::bad length" when connTLSWrite is called second time with smaller buffer (#1737)
  • Fix temp file leak druing replication error handling (#1721)
  • Fix ACL LOAD crash on replica since the primary client don't has a user (#1842)
  • Fix RANDOMKEY infinite loop during CLIENT PAUSE (#1850)
  • fix: add samples to stream object consumer trees (#1825)
  • Fix cluster slot stats assertion during promotion of replica (#1950)
  • Fix panic in primary when blocking shutdown after previous block with timeout (#1948)
  • Ignore stale gossip packets that arrive out of order (#1777)
  • Fix incorrect lag reported in XINFO GROUPS (#1952)
  • Avoid shard id update of replica if not matching with primary shard id (#573)

Security fixes

  • CVE-2025-21605 Limit output buffer for unauthenticated clients (#1993)

valkey-8.0.3-1.fc42

5 days 22 hours ago
FEDORA-2025-2ccc1f4ed9 Packages in this update:
  • valkey-8.0.3-1.fc42
Update description:

Valkey 8.0.3 - Released Wed 23 Apr 2025

Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.

Bug fixes

  • Optimize RDB load performance and fix cluster mode resizing on replica side (#1199)
  • Fix memory leak in forgotten node ping ext code path (#1574)
  • Fix cluster info sent stats for message with light header (#1563)
  • Fix module LatencyAddSample still work when latency-monitor-threshold is 0 (#1541)
  • Fix potential crash in radix tree recompression of huge keys (#1722)
  • Fix error "SSL routines::bad length" when connTLSWrite is called second time with smaller buffer (#1737)
  • Fix temp file leak druing replication error handling (#1721)
  • Fix ACL LOAD crash on replica since the primary client don't has a user (#1842)
  • Fix RANDOMKEY infinite loop during CLIENT PAUSE (#1850)
  • fix: add samples to stream object consumer trees (#1825)
  • Fix cluster slot stats assertion during promotion of replica (#1950)
  • Fix panic in primary when blocking shutdown after previous block with timeout (#1948)
  • Ignore stale gossip packets that arrive out of order (#1777)
  • Fix incorrect lag reported in XINFO GROUPS (#1952)
  • Avoid shard id update of replica if not matching with primary shard id (#573)

Security fixes

  • CVE-2025-21605 Limit output buffer for unauthenticated clients (#1993)

valkey-8.0.3-1.el8

5 days 22 hours ago
FEDORA-EPEL-2025-a73f52377d Packages in this update:
  • valkey-8.0.3-1.el8
Update description:

Valkey 8.0.3 - Released Wed 23 Apr 2025

Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.

Bug fixes

  • Optimize RDB load performance and fix cluster mode resizing on replica side (#1199)
  • Fix memory leak in forgotten node ping ext code path (#1574)
  • Fix cluster info sent stats for message with light header (#1563)
  • Fix module LatencyAddSample still work when latency-monitor-threshold is 0 (#1541)
  • Fix potential crash in radix tree recompression of huge keys (#1722)
  • Fix error "SSL routines::bad length" when connTLSWrite is called second time with smaller buffer (#1737)
  • Fix temp file leak druing replication error handling (#1721)
  • Fix ACL LOAD crash on replica since the primary client don't has a user (#1842)
  • Fix RANDOMKEY infinite loop during CLIENT PAUSE (#1850)
  • fix: add samples to stream object consumer trees (#1825)
  • Fix cluster slot stats assertion during promotion of replica (#1950)
  • Fix panic in primary when blocking shutdown after previous block with timeout (#1948)
  • Ignore stale gossip packets that arrive out of order (#1777)
  • Fix incorrect lag reported in XINFO GROUPS (#1952)
  • Avoid shard id update of replica if not matching with primary shard id (#573)

Security fixes

  • CVE-2025-21605 Limit output buffer for unauthenticated clients (#1993)

redis-7.2.8-1.fc40

5 days 23 hours ago
FEDORA-2025-290b0c6e2b Packages in this update:
  • redis-7.2.8-1.fc40
Update description:

Redis 7.2.8 Released Wed 23 Apr 2025 12:00:00 IST

Update urgency: SECURITY: There are security fixes in the release.

Security fixes

  • (CVE-2025-21605) An unauthenticated client can cause an unlimited growth of output buffers

Bug fixes

  • Fix race condition issues between the main thread and module threads
  • RANDOMKEY - infinite loop during client pause
  • ShardID inconsistency when both primary and replica support it
Checked
20 minutes 30 seconds ago