Executive brief
Redis, a widely used in-memory data store, contains a vulnerability in how it handles certain database commands. An authenticated user could trigger a memory error that allows them to potentially take control of the server or execute unauthorized code. This could lead to a complete compromise of the data stored in Redis and the underlying system. Users should update to version 8.6.3 to resolve this issue.
Technical details
A use-after-free (UAF) vulnerability exists in Redis server versions 7.2.0 through 8.6.2 within the client unblocking logic. The root cause is a failure to handle error returns from the 'processCommandAndResetClient' function during the re-execution of a previously blocked command. If a blocked client is evicted from memory during this specific flow, the system may attempt to access memory that has already been freed. An authenticated attacker with network access can exploit this condition to achieve remote code execution (RCE). The vulnerability is addressed in Redis version 8.6.3.
Affected products
- Redis Redis >= 7.2.0, < 8.6.3
- Red Hat valkey Red Hat Enterprise Linux 10, 9.6 EUS
Timeline
- 2026-05-05: disclosed
- 2026-05-05: patched: Fixed in Redis version 8.6.3
- 2026-05-05: advisory
References
- https://github.com/redis/redis/releases/tag/8.6.3
- https://github.com/redis/redis/security/advisories/GHSA-93m2-935m-8rj3
- https://access.redhat.com/errata/RHSA-2026:25216
- https://access.redhat.com/errata/RHSA-2026:25219
- https://access.redhat.com/errata/RHSA-2026:25925
- https://access.redhat.com/errata/RHSA-2026:26306
- https://access.redhat.com/errata/RHSA-2026:26540