Vulnerability
Published 2026-09-17
Verified 2026-09-19

Redis cluster bus OOB read CVE-2026-92925 (CVSS 7.1); fix upstream 8.10.0

Red Hat Product Security (public_date 17 September 2026) documents CVE-2026-92925 in Redis community: the cluster bus packet parser for PING/PONG/MEET fails to validate null-termination on string-carrying extensions (CWE-125), enabling a remote attacker on an adjacent network to craft a malicious packet and trigger an out-of-bounds read — sensitive-info disclosure or remote DoS. Red Hat CVSS 3.1 base 7.1 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H); threat severity Important; CISA SSVC notes exploitation none. Upstream fix referenced via redis/redis PR #15263 / commit 37894fae and release tag 8.10.0. Red Hat CVE page lists mixed product package states (Affected / Will not fix / Not affected) — check RH advisory for your workload. No in-the-wild claim in RH/NVD snippets this pass. Primary: Red Hat CVE; secondary: upstream 8.10.0 release / NVD.

Product
Redis (community) — cluster bus / cluster mode
Versions
Redis community cluster-bus path prior to upstream 8.10.0 fix; Red Hat redis-consuming products: see RH CVE package_state (mixed)
CVSS
(CVSS 3.1, Red Hat Important)
Exploited in Australia?
unknown
Patch to
Upgrade Redis to upstream 8.10.0 or later (or apply vendor backport); review Red Hat errata for RH-packaged redis consumers

Primary: Red Hat — CVE-2026-92925 Redis cluster bus OOB read (17 Sep 2026) · Vendor: Redis upstream 8.10.0 release (fix referenced by RH) · CVE: CVE-2026-92925 · NVD — CVE-2026-92925; also redis/redis PR #15263

vulnerabilities network