Update docker.io/redis Docker tag to v8.10.1
Successfully upgraded the Docker container on the Database Host by means of Watchtower container with dependency update facilitated by Mend's Renovate Bot and on the Mastodon instance manually with Docker compose.
This MR contains the following updates:
| Package | Update | Change |
|---|---|---|
| docker.io/redis (source) | patch | 8.10.0-alpine → 8.10.1-alpine |
Release Notes
redis/redis (docker.io/redis)
v8.10.1
Update urgency: SECURITY: There are security fixes in the release.
Security fixes
- (CVE-2026-62356) Miscalculated buffer size in
CMSketchRDB loading may lead to heap OOB write - Out-of-bounds access in TopK heap cleanup path (MOD-15410)
- Use-after-free in the TLS pending-data list when a command closes another pending connection
- A malicious RDB payload with an out-of-range
SLOT_INFOslot id causes memory corruption during RDB loading, which may lead to Remote Code Execution - Vector Sets: missing node level validation when loading a vector set from RDB may lead to out-of-bounds access
- Vector Sets: use-after-free when
VREMmutates the HNSW graph while backgroundVSIMthreads are still running - Vector Sets: a negative
hnsw_search()return was treated as a huge unsigned count, reading past the end of the result arrays - TLS client certificate authentication bypass: a Common Name containing an embedded NUL byte was truncated, allowing a client to authenticate as another (possibly privileged) ACL user
- #15594 Use-after-free in the blocked-client list when reprocessing a command evicts another client blocked on the same key