Ad

CVE-2026-92925

HIGH CVSS 3.1: 7,1 EPSS 0.34%
Обновлено 18 сентября 2026
Redis
Параметр Значение
CVSS 7,1 (HIGH)
Тип уязвимости CWE-125 (Чтение за пределами буфера)
Поставщик Redis
Публичный эксплойт Нет

A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packets, fails to properly validate string-carrying extensions for null-termination. This oversight allows a remote attacker to craft a malicious packet, leading to an out-of-bounds read when the packet's payload is processed.

Successful exploitation of this vulnerability could result in the disclosure of sensitive information or a remote denial of service (DoS).

Характеристики атаки

Способ атаки
Смежная сеть
Нужен доступ к локальной сети
Сложность
Низкая
Легко эксплуатировать
Нужны права
Не требуются
Права не нужны
Участие пользователя
Не требуется
Не нужно действие пользователя

Последствия

Конфиденциальность
Низкое
Частичная утечка данных
Целостность
Нет
Нет модификации данных
Доступность
Высокое
Полный отказ в обслуживании

Строка CVSS v3.1

Уязвимые продукты

red hat:confidential compute attestation red hat:red hat hardened images red hat:red hat update infrastructure 5 red hat:red hat openshift ai (rhoai) red hat:red hat ai inference server red hat:red hat ansible automation platform 2 red hat:red hat openstack platform 16.2 red hat:red hat openshift container platform 4 red hat:pen drive powered by red hat lightspeed red hat:logging subsystem for red hat openshift red hat:red hat enterprise linux 9 red hat:red hat 3scale api management platform 2 red hat:red hat openstack platform 17.1 red hat:red hat enterprise linux 8 red hat:red hat openstack platform 18.0 red hat:red hat openshift update service red hat:red hat developer hub red hat:red hat quay 3 red hat:red hat enterprise linux 10 red hat:red hat enterprise linux ai (rhel ai) 3 red hat:red hat connectivity link 1 red hat:red hat satellite 6