Skip to content

[stable/redis-ha] Redis 8.2.3#385

Open
fmmatthewzeemann wants to merge 1 commit intoDandyDeveloper:masterfrom
fmmatthewzeemann:feature/redis/8-2-3
Open

[stable/redis-ha] Redis 8.2.3#385
fmmatthewzeemann wants to merge 1 commit intoDandyDeveloper:masterfrom
fmmatthewzeemann:feature/redis/8-2-3

Conversation

@fmmatthewzeemann
Copy link

@fmmatthewzeemann fmmatthewzeemann commented Feb 12, 2026

What this PR does / why we need it:

Bumps the default Redis image from 8.2.2-alpine to 8.2.3-alpine to fix CVE-2025-62507 a stack-based buffer overflow in the XACK/XDEL commands that may lead to remote code execution (CVSS 3.1: 8.8 HIGH).

Special notes for your reviewer:

Patch release only — no breaking changes. Redis 8.2.3 is backward-compatible with 8.2.2 (RDB files load cleanly).

Fixes CVE-2025-62507 — stack-based buffer overflow in XACK/XDEL
commands (CVSS 3.1: 8.8 HIGH). Affects Redis 8.2.0 through 8.2.2.

- Bump image tag from 8.2.2-alpine to 8.2.3-alpine
- Bump chart version from 4.35.7 to 4.35.8
- Bump appVersion from 8.2.2 to 8.2.3
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant