CVE-2026-92925

HIGH CVSS 3.1: 7.1 EPSS 0.34%
Updated Sep 18, 2026
Redis
Parameter Value
CVSS 7.1 (HIGH)
Type CWE-125 (Out-of-bounds Read)
Vendor Redis
Public PoC No

A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packets, fails to properly validate string-carrying extensions for null-termination. This oversight allows a remote attacker to craft a malicious packet, leading to an out-of-bounds read when the packet's payload is processed.

Successful exploitation of this vulnerability could result in the disclosure of sensitive information or a remote denial of service (DoS).

Attack Parameters

Attack Vector
Adjacent
Requires local network access
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
None
No data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products

red hat:confidential compute attestation red hat:red hat hardened images red hat:red hat update infrastructure 5 red hat:red hat openshift ai (rhoai) red hat:red hat ai inference server red hat:red hat ansible automation platform 2 red hat:red hat openstack platform 16.2 red hat:red hat openshift container platform 4 red hat:pen drive powered by red hat lightspeed red hat:logging subsystem for red hat openshift red hat:red hat enterprise linux 9 red hat:red hat 3scale api management platform 2 red hat:red hat openstack platform 17.1 red hat:red hat enterprise linux 8 red hat:red hat openstack platform 18.0 red hat:red hat openshift update service red hat:red hat developer hub red hat:red hat quay 3 red hat:red hat enterprise linux 10 red hat:red hat enterprise linux ai (rhel ai) 3 red hat:red hat connectivity link 1 red hat:red hat satellite 6