Описание
An out-of-bounds read vulnerability in Redis through 8.8.1 allows an adjacent unauthenticated attacker to cause denial of service or information disclosure by sending a specially crafted PING message to the Redis Cluster Bus port.
Отчет
This CVE has been marked as rejected by the assigning CNA.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | valkey | Affected | ||
| Red Hat Enterprise Linux 8 | redis:6/redis | Affected | ||
| Red Hat Enterprise Linux 9 | redis | Affected | ||
| Red Hat Enterprise Linux 9 | redis:7/redis | Affected | ||
| Red Hat Enterprise Linux 9 | valkey | Not affected | ||
| Red Hat Hardened Images | valkey-main-9.0.5-0.1.hum1 | Fixed | RHSA-2026:43236 | 22.07.2026 |
Показывать по
10
Дополнительная информация
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2513105redis: Redis: Denial of Service via Out-of-Bounds Read in Cluster Bus
Связанные уязвимости
ubuntu
19 дней назад
Rejected reason: Red Hat CNA-LR concluded that this CVE is not valid.
CVSS3: 7.1
github
19 дней назад
An out-of-bounds read vulnerability in Redis through 8.8.1 allows an adjacent unauthenticated attacker to cause denial of service or information disclosure by sending a specially crafted PING message to the Redis Cluster Bus port.