Bug 2525226 (CVE-2026-81934)

Summary: CVE-2026-81934 redis: Redis: Arbitrary code execution via TLS pending-data list use-after-free
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: abarbaro, akhatavk, akostadi, alinfoot, alizardo, amasferr, amctagga, anthomas, aoconnor, aos-team-art-private, aprice, aruklets, asdas, bbrownin, bniver, brasmith, cmyers, cochase, derez, dmayorov, dnakabaa, doconnor, dpaolell, dranck, dschmidt, dtrifiro, eglynn, ehelms, eshamard, flucifre, ggainey, gmeno, groman, ilpinto, jcantril, jchui, jdelft, jdobes, jhe, jjoyce, jlanda, jlledo, jmitchel, jpasqual, jpretori, jsamir, jschluet, jupierce, juwatts, jvasik, kaycoth, kgaikwad, kshier, ktsao, lbrazdil, lcouzens, lgarciaa, lhh, ltomasbo, mbenjamin, mbiarnes, mburns, mdellweg, mgarciac, mhackett, mhulan, mminar, nboldt, nmoumoul, oaljalju, oezr, orabin, osousa, pantinor, pcreech, ppalepu, ppostler, prdhamdh, psrna, rbiba, rblanco, rbryant, rchan, rekumar, rhel-process-autobot, rjohnson, rojacob, sghai, sidsharm, simaishi, smallamp, sostapov, sskracic, stcannon, suppawar, teagle, tmalecek, tpfromme, tsedmik, vereddy, vlaad, vvoronko, watson-tool-maintainers, weaton, xiaoxwan, yguenane, ykashtan, zzhou
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Redis. This vulnerability, a use-after-free, exists within the `tlsProcessPendingData()` function, which manages the Transport Layer Security (TLS) pending-data list when Redis is configured with TLS support. A remote, unauthenticated attacker could exploit this to execute unauthorized commands with the same privileges as the Redis server.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-08-27 20:18:07 UTC
Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands with the privileges of the Redis server. Fixed in Redis 8.2.9, 8.4.6, 8.6.6, 8.8.2, and 8.10.1.