Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-66373

Опубликовано: 25 июл. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.

A flaw was found in Redis. An authenticated attacker, in an unusual configuration where they can execute the RESTORE command, could exploit a double free vulnerability. This occurs when a specially crafted RESTORE payload references the same NACK (pending entry) by multiple consumers, and both consumers are subsequently deleted via XGROUP DELCONSUMER. Successful exploitation of this flaw could lead to remote code execution.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10valkeyAffected
Red Hat Enterprise Linux 8redis:6/redisAffected
Red Hat Enterprise Linux 9redisAffected
Red Hat Enterprise Linux 9redis:7/redisAffected
Red Hat Enterprise Linux 9valkeyAffected
Red Hat Hardened ImagesboostNot affected
Red Hat Hardened Imagesvalkey-main-9.0.5-0.1.hum1FixedRHSA-2026:4323622.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1341
https://bugzilla.redhat.com/show_bug.cgi?id=2506985redis: Redis: Remote Code Execution via specially crafted RESTORE payload

EPSS

Процентиль: 57%
0.00887
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 месяцев назад

Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.

CVSS3: 7.5
nvd
около 2 месяцев назад

Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.

msrc
около 2 месяцев назад

Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.

CVSS3: 7.5
debian
около 2 месяцев назад

Redis before 8.8.0, in the unusual case where an authenticated attacke ...

suse-cvrf
29 дней назад

Security update for redis7

EPSS

Процентиль: 57%
0.00887
Низкий

7.5 High

CVSS3