Update docker.io/redis Docker tag to v8.10.1

Share
Update docker.io/redis Docker tag to v8.10.1
Photo by Silas Köhler / Unsplash

Successfully upgraded the Docker container on the Database Host by means of Watchtower container with dependency update facilitated by Mend's Renovate Bot and on the Mastodon instance manually with Docker compose.

This MR contains the following updates:

Package Update Change
docker.io/redis (source) patch 8.10.0-alpine → 8.10.1-alpine

Release Notes

redis/redis (docker.io/redis)

v8.10.1

Compare Source

Update urgency: SECURITY: There are security fixes in the release.

Security fixes
  • (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write
  • Out-of-bounds access in TopK heap cleanup path (MOD-15410)
  • Use-after-free in the TLS pending-data list when a command closes another pending connection
  • A malicious RDB payload with an out-of-range SLOT_INFO slot id causes memory corruption during RDB loading, which may lead to Remote Code Execution
  • Vector Sets: missing node level validation when loading a vector set from RDB may lead to out-of-bounds access
  • Vector Sets: use-after-free when VREM mutates the HNSW graph while background VSIM threads are still running
  • Vector Sets: a negative hnsw_search() return was treated as a huge unsigned count, reading past the end of the result arrays
  • TLS client certificate authentication bypass: a Common Name containing an embedded NUL byte was truncated, allowing a client to authenticate as another (possibly privileged) ACL user
  • #​15594 Use-after-free in the blocked-client list when reprocessing a command evicts another client blocked on the same key

Read more

Me on Mastodon - This link is here for verification purposes.