GHSA-3gvw-xg56-j2xmMediumCVSS 7.1
In Redis community the cluster bus PING/PONG/MEET packet parser validated extension padding and...
🔗 CVE IDs covered (1)
📋 Description
In Redis community the cluster bus PING/PONG/MEET packet parser validated extension padding and total length but never checked that string-carrying extensions are properly null-terminated, allowing a crafted packet to trigger out-of-bounds reads when the payload is later consumed as a C string. This vulnerability can potentially lead to loss of confidentiality or remote denial of service. Redis Software / Redis Enterprise are not affected by this issue.
🔗 References (10)
- https://nvd.nist.gov/vuln/detail/CVE-2026-92925
- https://github.com/redis/redis/pull/15263
- https://github.com/redis/redis/commit/37894faeea11e2db28b9fc2af378a762d2c36523
- https://github.com/redis/redis/releases/tag/8.10.0
- https://access.redhat.com/security/cve/CVE-2026-92925
- https://bugzilla.redhat.com/show_bug.cgi?id=2535971
- https://access.redhat.com/errata/RHSA-2026:69521
- https://access.redhat.com/errata/RHSA-2026:69520
- https://access.redhat.com/errata/RHSA-2026:65120
- https://github.com/advisories/GHSA-3gvw-xg56-j2xm