PT-2026-69452 · Redis · Redis
CVSS v3.1
7.1
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Redis versions prior to 8.8.2
Description
An out-of-bounds read occurs when the
getPingExtLength() function in the cluster bus message parser fails to validate extension length fields against the actual remaining buffer size. This allows an adjacent unauthenticated attacker to cause a denial of service or information disclosure by sending a specially crafted PING message to the Redis Cluster Bus port, forcing the parser to read beyond the allocated buffer boundary.Recommendations
Update Redis to version 8.8.2 or later.
Exploit
Fix
DoS
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Redis