Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package redis for openSUSE:Factory checked 
in at 2026-08-18 16:35:41
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/redis (Old)
 and      /work/SRC/openSUSE:Factory/.redis.new.1258 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "redis"

Tue Aug 18 16:35:41 2026 rev:20 rq:1371613 version:8.10.1

Changes:
--------
--- /work/SRC/openSUSE:Factory/redis/redis.changes      2026-08-06 
16:18:17.252248083 +0200
+++ /work/SRC/openSUSE:Factory/.redis.new.1258/redis.changes    2026-08-18 
16:36:01.671951011 +0200
@@ -1,0 +2,30 @@
+Mon Aug 17 17:05:06 UTC 2026 - Marcus Rueckert <[email protected]>
+
+- Update to 8.10.1
+  Update urgency: SECURITY: There are security fixes in the release.
+
+  - Security fixes
+    - (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB
+      loading may lead to heap OOB write
+    - Out-of-bounds access in TopK heap cleanup path (MOD-15410)
+    - Use-after-free in the TLS pending-data list when a command
+      closes another pending connection
+    - A malicious RDB payload with an out-of-range SLOT_INFO slot
+      id causes memory corruption during RDB loading, which may
+      lead to Remote Code Execution
+    - Vector Sets: missing node level validation when loading a
+      vector set from RDB may lead to out-of-bounds access
+    - Vector Sets: use-after-free when VREM mutates the HNSW graph
+      while background VSIM threads are still running
+    - Vector Sets: a negative hnsw_search() return was treated as a
+      huge unsigned count, reading past the end of the result
+      arrays
+    - TLS client certificate authentication bypass: a Common Name
+      containing an embedded NUL byte was truncated, allowing a
+      client to authenticate as another (possibly privileged) ACL
+      user
+    - #15594 Use-after-free in the blocked-client list when
+      reprocessing a command evicts another client blocked on the
+      same key
+
+-------------------------------------------------------------------

Old:
----
  redis-8.10.0.tar.gz

New:
----
  redis-8.10.1.tar.gz

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ redis.spec ++++++
--- /var/tmp/diff_new_pack.E5WvuN/_old  2026-08-18 16:36:02.804991545 +0200
+++ /var/tmp/diff_new_pack.E5WvuN/_new  2026-08-18 16:36:02.806991617 +0200
@@ -50,7 +50,7 @@
 %define _conf_dir      %{_sysconfdir}/%{origname}
 %define _module_dir    %{_libdir}/%{origname}/modules
 Name:           %{origname}%{psuffix}
-Version:        8.10.0
+Version:        8.10.1
 Release:        0
 Summary:        Persistent key-value database
 License:        AGPL-3.0-only

++++++ _service ++++++
--- /var/tmp/diff_new_pack.E5WvuN/_old  2026-08-18 16:36:02.881994300 +0200
+++ /var/tmp/diff_new_pack.E5WvuN/_new  2026-08-18 16:36:02.886994479 +0200
@@ -10,15 +10,16 @@
        Both are mode="manual" (they need network access): after a version bump
        run "osc service manualrun" and remember to update the tarball name in
        the "src" parameter below. -->
+  <service name="download_files" mode="manual" />
   <service name="cargo_vendor" mode="manual">
-    <param name="src">redis-8.10.0.tar.gz</param>
+    <param name="src">redis-8.10.1.tar.gz</param>
     <param name="custom-root">modules/redisjson/src</param>
     <param name="tag">redisjson</param>
     <param name="update">false</param>
     <param name="respect-lockfile">true</param>
   </service>
   <service name="cargo_vendor" mode="manual">
-    <param name="src">redis-8.10.0.tar.gz</param>
+    <param name="src">redis-8.10.1.tar.gz</param>
     <param name="custom-root">modules/redisearch/src/src/redisearch_rs</param>
     <param name="tag">redisearch</param>
     <param name="update">false</param>

++++++ redis-8.10.0.tar.gz -> redis-8.10.1.tar.gz ++++++
/work/SRC/openSUSE:Factory/redis/redis-8.10.0.tar.gz 
/work/SRC/openSUSE:Factory/.redis.new.1258/redis-8.10.1.tar.gz differ: char 18, 
line 1

++++++ redis.hashes ++++++
--- /var/tmp/diff_new_pack.E5WvuN/_old  2026-08-18 16:36:03.001998593 +0200
+++ /var/tmp/diff_new_pack.E5WvuN/_new  2026-08-18 16:36:03.005998736 +0200
@@ -242,4 +242,12 @@
 hash redis-8.6.5.tar.gz sha256 
cd04337495fda9be071d4e1e3c6a61134f83995bd23d1794cad18f878b7012ad 
http://download.redis.io/releases/redis-8.6.5.tar.gz
 hash redis-8.8.1.tar.gz sha256 
1d1e423c9c808de3cb01dd3300d2b8d305b7691382e31a847ec17b66d3157477 
http://download.redis.io/releases/redis-8.8.1.tar.gz
 hash redis-8.10.0.tar.gz sha256 
f1baa4b28befd417aa6577ebeedde9e9fc7814cfcc299b2a6d2fd99ef7420a6c 
http://download.redis.io/releases/redis-8.10.0.tar.gz
+hash redis-6.2.24.tar.gz sha256 
c3f112749c7cb108597713469cc9beed305e91f036fba313ce8dcbad829f5821 
http://download.redis.io/releases/redis-6.2.24.tar.gz
+hash redis-7.4.11.tar.gz sha256 
3c266ece0abd54ed3b1c912c6eb86b7508cf382cb690ee6649d3843f018f6357 
http://download.redis.io/releases/redis-7.4.11.tar.gz
+hash redis-8.2.9.tar.gz sha256 
531b314e5557ad76d941f605b3e3162ac61dc141f37c407e1f91fcfe17ea8c30 
http://download.redis.io/releases/redis-8.2.9.tar.gz
+hash redis-8.4.6.tar.gz sha256 
de695b64c76ffb783ab441e78de5fb877f33e1e62cbacad6ab825205e62b1e5b 
http://download.redis.io/releases/redis-8.4.6.tar.gz
+hash redis-8.6.6.tar.gz sha256 
8b1b04f77910780a141bef7d66990d2f6171209ce615dbedbfa3b82ebfaf0887 
http://download.redis.io/releases/redis-8.6.6.tar.gz
+hash redis-8.8.2.tar.gz sha256 
328ccd441d5ef22e00c81cbcd088007887fdfd2fabb32c663998f29033acdb25 
http://download.redis.io/releases/redis-8.8.2.tar.gz
+hash redis-8.10.1.tar.gz sha256 
60166c95ab7aedaa9dfe516de685be0a4dd87be95ded59ba429df14c13f1b663 
http://download.redis.io/releases/redis-8.10.1.tar.gz
+hash redis-7.2.16.tar.gz sha256 
960a8ec15e34ff40e57ff16837b26b33bd81f2da6d24497bb63de532a323a18e 
http://download.redis.io/releases/redis-7.2.16.tar.gz
 

Reply via email to