Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-23631

Опубликовано: 05 мая 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled or can be disabled, which may lead to remote code execution. A workaround is to prevent users from executing Lua scripts or avoid using replicas where replica-read-only is disabled. This is patched in version 8.6.3.

A flaw was found in Redis, an in-memory data structure store. An authenticated attacker can exploit a use-after-free vulnerability in redis-server with Lua scripting. This occurs through the master-replica synchronization mechanism on replicas where replica-read-only is disabled or can be disabled. Successful exploitation may lead to remote code execution.

Отчет

This Important vulnerability in Redis affects instances configured with Lua scripting and operating as replicas where the replica-read-only setting is disabled or can be modified by an authenticated attacker. Exploitation of a use-after-free flaw during master-replica synchronization could lead to remote code execution. The risk is present in deployments where Redis replicas are configured for write operations or lack sufficient access controls to prevent modification of the replica-read-only setting.

Меры по смягчению последствий

To mitigate this flaw, ensure that Redis replicas maintain replica-read-only as enabled and prevent its modification by unauthorized users. If Lua scripting is not a required feature, consider disabling it to reduce the attack surface. Restricting network access to Redis instances to trusted clients can also limit exposure. For Redis configuration, edit the redis.conf file to include or verify: replica-read-only yes After modifying the configuration, restart the Redis service for the changes to take effect. This action will temporarily interrupt service availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8redis:6/redisUnder investigation
Red Hat Enterprise Linux 9redisUnder investigation
Red Hat Hardened ImagesboostNot affected
Red Hat Hardened ImagesvalkeyAffected
Red Hat Enterprise Linux 10valkeyFixedRHSA-2026:2521611.06.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportvalkeyFixedRHSA-2026:2654017.06.2026
Red Hat Enterprise Linux 9redisFixedRHSA-2026:2521911.06.2026
Red Hat Enterprise Linux 9valkeyFixedRHSA-2026:2592515.06.2026
Red Hat Enterprise Linux 9.4 Update Services for SAP SolutionsredisFixedRHSA-2026:3344430.06.2026
Red Hat Enterprise Linux 9.6 Extended Update SupportredisFixedRHSA-2026:2630616.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2466788redis: Remote code execution via use-after-free in Lua scripting

EPSS

Процентиль: 76%
0.01782
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
3 месяца назад

Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled or can be disabled, which may lead to remote code execution. A workaround is to prevent users from executing Lua scripts or avoid using replicas where replica-read-only is disabled. This is patched in version 8.6.3.

CVSS3: 8.1
nvd
3 месяца назад

Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled or can be disabled, which may lead to remote code execution. A workaround is to prevent users from executing Lua scripts or avoid using replicas where replica-read-only is disabled. This is patched in version 8.6.3.

msrc
около 2 месяцев назад

redis-server Lua use-after-free may allow remote code execution

CVSS3: 8.1
debian
3 месяца назад

Redis is an in-memory data structure store. In all versions of redis-s ...

github
3 месяца назад

Lua Use-After-Free may lead to remote code execution

EPSS

Процентиль: 76%
0.01782
Низкий

8.8 High

CVSS3