Количество 21
Количество 21
GHSA-93m2-935m-8rj3
Use-After-Free in unblock client flow may lead to remote code execution
CVE-2026-23479
Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated attacker can trigger a use-after-free that may lead to remote code execution. This has been patched in version 8.6.3.
CVE-2026-23479
Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated attacker can trigger a use-after-free that may lead to remote code execution. This has been patched in version 8.6.3.
CVE-2026-23479
Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated attacker can trigger a use-after-free that may lead to remote code execution. This has been patched in version 8.6.3.
CVE-2026-23479
redis-server use-after-free in unblock client flow may allow remote code execution
CVE-2026-23479
Redis is an in-memory data structure store. In redis-server from 7.2.0 ...
ROS-20260803-80-0004
Уязвимость redis
ROS-20260803-73-0004
Уязвимость redis
ROS-20260708-80-0045
Уязвимость valkey
ROS-20260708-73-0036
Уязвимость valkey
BDU:2026-06444
Уязвимость функции processCommandAndResetClient() системы управления базами данных (СУБД) Redis, позволяющая нарушителю выполнить произвольный код
SUSE-SU-2026:2099-1
Security update for redis
SUSE-SU-2026:1950-1
Security update for valkey
SUSE-SU-2026:1949-1
Security update for valkey
RLSA-2026:25925
Important: valkey security update
RLSA-2026:25219
Important: redis:7 security update
RLSA-2026:25216
Important: valkey security update
ELSA-2026-25925
ELSA-2026-25925: valkey security update (IMPORTANT)
ELSA-2026-25219
ELSA-2026-25219: redis:7 security update (IMPORTANT)
ELSA-2026-25216
ELSA-2026-25216: valkey security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-93m2-935m-8rj3 Use-After-Free in unblock client flow may lead to remote code execution | 1% Низкий | 5 месяцев назад | ||
CVE-2026-23479 Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated attacker can trigger a use-after-free that may lead to remote code execution. This has been patched in version 8.6.3. | CVSS3: 8.8 | 1% Низкий | 5 месяцев назад | |
CVE-2026-23479 Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated attacker can trigger a use-after-free that may lead to remote code execution. This has been patched in version 8.6.3. | CVSS3: 7.5 | 1% Низкий | 5 месяцев назад | |
CVE-2026-23479 Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated attacker can trigger a use-after-free that may lead to remote code execution. This has been patched in version 8.6.3. | CVSS3: 8.8 | 1% Низкий | 5 месяцев назад | |
CVE-2026-23479 redis-server use-after-free in unblock client flow may allow remote code execution | 1% Низкий | 4 месяца назад | ||
CVE-2026-23479 Redis is an in-memory data structure store. In redis-server from 7.2.0 ... | CVSS3: 8.8 | 1% Низкий | 5 месяцев назад | |
ROS-20260803-80-0004 Уязвимость redis | CVSS3: 8.8 | 1% Низкий | около 2 месяцев назад | |
ROS-20260803-73-0004 Уязвимость redis | CVSS3: 8.8 | 1% Низкий | около 2 месяцев назад | |
ROS-20260708-80-0045 Уязвимость valkey | CVSS3: 8.8 | 1% Низкий | 2 месяца назад | |
ROS-20260708-73-0036 Уязвимость valkey | CVSS3: 8.8 | 1% Низкий | 2 месяца назад | |
BDU:2026-06444 Уязвимость функции processCommandAndResetClient() системы управления базами данных (СУБД) Redis, позволяющая нарушителю выполнить произвольный код | CVSS3: 8.8 | 1% Низкий | 5 месяцев назад | |
SUSE-SU-2026:2099-1 Security update for redis | 4 месяца назад | |||
SUSE-SU-2026:1950-1 Security update for valkey | 4 месяца назад | |||
SUSE-SU-2026:1949-1 Security update for valkey | 4 месяца назад | |||
RLSA-2026:25925 Important: valkey security update | 3 месяца назад | |||
RLSA-2026:25219 Important: redis:7 security update | 3 месяца назад | |||
RLSA-2026:25216 Important: valkey security update | 3 месяца назад | |||
ELSA-2026-25925 ELSA-2026-25925: valkey security update (IMPORTANT) | 3 месяца назад | |||
ELSA-2026-25219 ELSA-2026-25219: redis:7 security update (IMPORTANT) | 3 месяца назад | |||
ELSA-2026-25216 ELSA-2026-25216: valkey security update (IMPORTANT) | 2 месяца назад |
Уязвимостей на страницу