Количество 11
Количество 11
GHSA-c964-568j-vxx7
Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.
CVE-2026-66373
Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.
CVE-2026-66373
Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.
CVE-2026-66373
Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.
CVE-2026-66373
Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.
CVE-2026-66373
Redis before 8.8.0, in the unusual case where an authenticated attacke ...
SUSE-SU-2026:3639-1
Security update for redis7
SUSE-SU-2026:3638-1
Security update for redis
SUSE-SU-2026:3637-1
Security update for redis
SUSE-SU-2026:3636-1
Security update for redis7
BDU:2026-10490
Уязвимость системы управления базами данных (СУБД) Redis, связанная с ошибкой повторного освобождения памяти, позволяющая нарушителю выполнить произвольный код
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-c964-568j-vxx7 Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243. | CVSS3: 7.5 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-66373 Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243. | CVSS3: 7.5 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-66373 Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243. | CVSS3: 7.5 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-66373 Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243. | CVSS3: 7.5 | 1% Низкий | около 2 месяцев назад | |
CVE-2026-66373 Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243. | 1% Низкий | около 2 месяцев назад | ||
CVE-2026-66373 Redis before 8.8.0, in the unusual case where an authenticated attacke ... | CVSS3: 7.5 | 1% Низкий | около 2 месяцев назад | |
SUSE-SU-2026:3639-1 Security update for redis7 | 1% Низкий | 30 дней назад | ||
SUSE-SU-2026:3638-1 Security update for redis | 1% Низкий | 30 дней назад | ||
SUSE-SU-2026:3637-1 Security update for redis | 1% Низкий | 30 дней назад | ||
SUSE-SU-2026:3636-1 Security update for redis7 | 1% Низкий | 30 дней назад | ||
BDU:2026-10490 Уязвимость системы управления базами данных (СУБД) Redis, связанная с ошибкой повторного освобождения памяти, позволяющая нарушителю выполнить произвольный код | CVSS3: 7.5 | 1% Низкий | около 2 месяцев назад |
Уязвимостей на страницу