Redis: redis: out-of-bounds read via crafted cluster bus packets
21Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 7.1epss 0.6%
probabilidade de exploração
0.6%top 55% das CVEs
exploração observada
nãonenhuma fonte reporta
A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packets, fails to properly validate string-carrying extensions for null-termination. This oversight allows a remote attacker to craft a malicious packet, leading to an out-of-bounds read when the packet's payload is processed. Successful exploitation of this vulnerability could result in the disclosure of sensitive information or a remote denial of service (DoS).
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Produtos afetados
Red Hat · Pen Drive Powered by Red Hat LightspeedRed Hat · Red Hat 3scale API Management Platform 2Red Hat · Red Hat Enterprise Linux 10Red Hat · Red Hat Enterprise Linux 8Red Hat · Red Hat Enterprise Linux 9Red Hat · Red Hat Enterprise Linux 9.4 Update Services for SAP SolutionsRed Hat · Red Hat Enterprise Linux 9.6 Extended Update SupportRed Hat · Red Hat Hardened ImagesReferências
https://access.redhat.com/errata/RHSA-2026:65120https://access.redhat.com/errata/RHSA-2026:69520https://access.redhat.com/errata/RHSA-2026:69521https://access.redhat.com/security/cve/CVE-2026-92925https://bugzilla.redhat.com/show_bug.cgi?id=2535971https://github.com/redis/redis/commit/37894faeea11e2db28b9fc2af378a762d2c36523https://github.com/redis/redis/pull/15263https://github.com/redis/redis/releases/tag/8.10.0