Junglewise Threat Intelligence

CVE-2026-23479: Redis use-after-free in unblock client flow

CVE-2026-23479 · Severity: high · CVSS 8.8 · Published 2026-05-05

Vendors: Red Hat.

Executive brief

Redis, a widely used in-memory data store, contains a vulnerability in how it handles certain database commands. An authenticated user could trigger a memory error that allows them to potentially take control of the server or execute unauthorized code. This could lead to a complete compromise of the data stored in Redis and the underlying system. Users should update to version 8.6.3 to resolve this issue.

Technical details

A use-after-free (UAF) vulnerability exists in Redis server versions 7.2.0 through 8.6.2 within the client unblocking logic. The root cause is a failure to handle error returns from the 'processCommandAndResetClient' function during the re-execution of a previously blocked command. If a blocked client is evicted from memory during this specific flow, the system may attempt to access memory that has already been freed. An authenticated attacker with network access can exploit this condition to achieve remote code execution (RCE). The vulnerability is addressed in Redis version 8.6.3.

Affected products

  • Redis Redis >= 7.2.0, < 8.6.3
  • Red Hat valkey Red Hat Enterprise Linux 10, 9.6 EUS

Timeline

  • 2026-05-05: disclosed
  • 2026-05-05: patched: Fixed in Redis version 8.6.3
  • 2026-05-05: advisory

References