Описание
Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from processCommandAndResetClient when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated attacker can trigger a use-after-free that may lead to remote code execution. This has been patched in version 8.6.3.
A flaw was found in Redis. The unblock client flow does not handle an error return from the processCommandAndResetClient when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated attacker can cause a use-after-free issue. This potentially leads to arbitrary code execution.
Отчет
To exploit this flaw, a highly specific sequence of events and time dependent conditions that are not directly in control of an attacker must occur, increasing the complexity of exploitation. Additionally, the attacker needs to be authenticated, limiting the exposure of this issue. To reflect these conditions, this vulnerability has been rated with an important severity.
Меры по смягчению последствий
Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 8 | redis:6/redis | Not affected | ||
| Red Hat Enterprise Linux 9 | redis | Not affected | ||
| Red Hat Enterprise Linux 10 | valkey | Fixed | RHSA-2026:25216 | 11.06.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | valkey | Fixed | RHSA-2026:26540 | 17.06.2026 |
| Red Hat Enterprise Linux 9 | redis | Fixed | RHSA-2026:25219 | 11.06.2026 |
| Red Hat Enterprise Linux 9 | valkey | Fixed | RHSA-2026:25925 | 15.06.2026 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | redis | Fixed | RHSA-2026:26306 | 16.06.2026 |
| Red Hat Hardened Images | valkey-main-9.0.4-0.1.hum1 | Fixed | RHSA-2026:14316 | 06.05.2026 |
| Red Hat Hardened Images | boost-main-1.90.0-7.hum1 | Fixed | RHSA-2026:7662 | 11.04.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated attacker can trigger a use-after-free that may lead to remote code execution. This has been patched in version 8.6.3.
Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated attacker can trigger a use-after-free that may lead to remote code execution. This has been patched in version 8.6.3.
redis-server use-after-free in unblock client flow may allow remote code execution
Redis is an in-memory data structure store. In redis-server from 7.2.0 ...
Use-After-Free in unblock client flow may lead to remote code execution
EPSS
7.5 High
CVSS3