Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-23479

Опубликовано: 05 мая 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from processCommandAndResetClient when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated attacker can trigger a use-after-free that may lead to remote code execution. This has been patched in version 8.6.3.

A flaw was found in Redis. The unblock client flow does not handle an error return from the processCommandAndResetClient when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated attacker can cause a use-after-free issue. This potentially leads to arbitrary code execution.

Отчет

To exploit this flaw, a highly specific sequence of events and time dependent conditions that are not directly in control of an attacker must occur, increasing the complexity of exploitation. Additionally, the attacker needs to be authenticated, limiting the exposure of this issue. To reflect these conditions, this vulnerability has been rated with an important severity.

Меры по смягчению последствий

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8redis:6/redisNot affected
Red Hat Enterprise Linux 9redisNot affected
Red Hat Enterprise Linux 10valkeyFixedRHSA-2026:2521611.06.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportvalkeyFixedRHSA-2026:2654017.06.2026
Red Hat Enterprise Linux 9redisFixedRHSA-2026:2521911.06.2026
Red Hat Enterprise Linux 9valkeyFixedRHSA-2026:2592515.06.2026
Red Hat Enterprise Linux 9.6 Extended Update SupportredisFixedRHSA-2026:2630616.06.2026
Red Hat Hardened Imagesvalkey-main-9.0.4-0.1.hum1FixedRHSA-2026:1431606.05.2026
Red Hat Hardened Imagesboost-main-1.90.0-7.hum1FixedRHSA-2026:766211.04.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2466780redis: use-after-free in unblock client flow may allow remote code execution

EPSS

Процентиль: 67%
0.01286
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
3 месяца назад

Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated attacker can trigger a use-after-free that may lead to remote code execution. This has been patched in version 8.6.3.

CVSS3: 8.8
nvd
3 месяца назад

Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated attacker can trigger a use-after-free that may lead to remote code execution. This has been patched in version 8.6.3.

msrc
около 2 месяцев назад

redis-server use-after-free in unblock client flow may allow remote code execution

CVSS3: 8.8
debian
3 месяца назад

Redis is an in-memory data structure store. In redis-server from 7.2.0 ...

github
3 месяца назад

Use-After-Free in unblock client flow may lead to remote code execution

EPSS

Процентиль: 67%
0.01286
Низкий

7.5 High

CVSS3