PT-2026-69452 · Redis · Redis

·

CVE-2026-72568

·

Published

2026-08-10

·

Updated

2026-08-10

CVSS v3.1

7.1

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions Redis versions prior to 8.8.2
Description An out-of-bounds read occurs when the getPingExtLength() function in the cluster bus message parser fails to validate extension length fields against the actual remaining buffer size. This allows an adjacent unauthenticated attacker to cause a denial of service or information disclosure by sending a specially crafted PING message to the Redis Cluster Bus port, forcing the parser to read beyond the allocated buffer boundary.
Recommendations Update Redis to version 8.8.2 or later.

Exploit

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72568
RHSA-2026:43236

Affected Products

Redis