Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia 9 MGASA-2023-0301 Moderate: Redis Race Condition Threat

mageia
Calendar Grey October 24, 2023
Dist Mageia Esm H88
MGASA-2023-0302: The new nginx version fixes a critical security flaw identified on October 26, 2023.
Redis upstream published a fix for CVE-2023-45145

Summary

Redis upstream published a fix for CVE-2023-45145.
CVE-2023-45145: The wrong order of listen(2) and chmod(2) calls creates a race condition that can be used by another process to bypass desired Unix socket permissions on startup.

References

- https://bugs.mageia.org/show_bug.cgi?id=32406

- https://github.com/redis/redis/releases/tag/7.0.14

- https://www.cve.org/CVERecord?id=CVE-2023-45145

Resolution

SRPMS

- 9/core/redis-7.0.14-1.mga9

Publication date: 24 Oct 2023
URL: https://advisories.mageia.org/MGASA-2023-0301.html
Type: security
CVE: CVE-2023-45145

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here