Mageia Redis Security Advisory: Fix for CVE-2023-45145 Race Condition Issue
Summary
Redis upstream published a fix for CVE-2023-45145.
CVE-2023-45145: The wrong order of listen(2) and chmod(2) calls creates
a race condition that can be used by another process to bypass desired
Unix socket permissions on startup.
References
- https://bugs.mageia.org/show_bug.cgi?id=32406
- https://github.com/redis/redis/releases/tag/7.0.14
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45145
Resolution
MGASA-2023-0301 - Updated redis package fixes a security vulnerability
SRPMS
- 9/core/redis-7.0.14-1.mga9