Advisories ยป MGASA-2023-0301

Updated redis package fixes a security vulnerability

Publication date: 24 Oct 2023
Modification date: 24 Oct 2023
Type: security
Affected Mageia releases : 9
CVE: CVE-2023-45145

Description

Redis upstream published a fix for CVE-2023-45145.

CVE-2023-45145: The wrong order of listen(2) and chmod(2) calls creates
a race condition that can be used by another process to bypass desired
Unix socket permissions on startup.
                

References

SRPMS

9/core