8.0.4
Update urgency: SECURITY: There are security fixes in the release.
Security fixes
- (CVE-2025-49844) A Lua script may lead to remote code execution
- (CVE-2025-46817) A Lua script may lead to integer overflow and potential RCE
- (CVE-2025-46818) A Lua script can be executed in the context of another user
- (CVE-2025-46819) LUA out-of-bound read
New Features
- #14223
VSIM: newEPSILONargument to specify maximum distance
Bug fixes
- #14330 Potential use-after-free after pubsub and Lua defrag
- #14319 Potential crash on Lua script defrag
- #14224
HINCRBYFLOATremoves field expiration on replica - #14164 Prevent
CLIENT UNBLOCKfrom unblockingCLIENT PAUSE - #14165 Endless client blocking for blocking commands
- #14144 Vector sets - RDB format is not compatible with big endian machines
- #14163
EVALcrash when error table is empty - #14143 Gracefully handle short read errors for hashes with TTL during full sync