Red HatCVE-2026-92925
Redis community: out-of-bounds read
High7.1CVE-2026-92925 · Published Sep 17, 2026 · updated Sep 22, 2026
A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packets, fails to properly validate string-carrying extensions for null-termination. This oversight allows a remote attacker to craft a malicious packet, leading to an out-of-bounds read when the packet's payload is processed. Successful exploitation of this vulnerability could result in the disclosure of sensitive information or a remote denial of service (DoS).
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Pen Drive Powered by Red Hat Lightspeed Product | all versions | No fix yet |
| Red Hat 3scale API Management Platform 2 Product | all versions | No fix yet |
| all versions | No fix yet | |
| all versions | No fix yet | |
| Red Hat Enterprise Linux 10 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 8 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 9 Product | all versions | No fix yet |
| all versions | No fix yet | |
| Red Hat Hardened Images Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-125
- www.cve.org/CVERecord?id=CVE-2026-92925
- nvd.nist.gov/vuln/detail/CVE-2026-92925
- access.redhat.com/errata/RHSA-2026:65120
- access.redhat.com/errata/RHSA-2026:69520
- access.redhat.com/errata/RHSA-2026:69521
- access.redhat.com/security/cve/CVE-2026-92925
- bugzilla.redhat.com/show_bug.cgi?id=2535971
- github.com/redis/redis/commit/37894faeea11e2db28b9fc2af378a762d2c36523
- github.com/redis/redis/pull/15263
- github.com/redis/redis/releases/tag/8.10.0
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 17 | Red Hat Keycloak.: capture-replay | High7.4 | 26.7.4 |
| Sep 17 | Red Hat libxml2: null pointer dereference | Medium5.5 | No fix yet |
| Sep 17 | Red Hat quarkus-websockets-next. This vulnerability: denial of service | High7.5 | No fix yet |
| Sep 17 | Red Hat SmallRye JWT: path traversal | Medium5.3 | No fix yet |
| Sep 17 | Red Hat bmctest: missing authentication | Medium5.3 | No fix yet |
| Sep 17 | Red Hat Satellite 6: improper authorization | Medium4.3 | No fix yet |