Bug 2535971 (CVE-2026-92925)

Summary: CVE-2026-92925 redis: Redis: Out-of-bounds read via crafted cluster bus packets
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: abarbaro, akhatavk, akostadi, alinfoot, alizardo, amasferr, anthomas, aos-team-art-private, aprice, asdas, bbrownin, blitton, brasmith, cmyers, cochase, dmayorov, dnakabaa, doconnor, dpaolell, dranck, dschmidt, dtrifiro, eglynn, ehelms, eshamard, ggainey, hoberger, ilpinto, jcantril, jchui, jdelft, jdobes, jhe, jholecek, jjoyce, jlanda, jlledo, jmitchel, jpasqual, jpretori, jsamir, jschluet, jupierce, juwatts, jvasik, kaycoth, kgaikwad, kshier, ktsao, lbrazdil, lcouzens, lgarciaa, lhh, lpele, ltomasbo, mbarnett, mbiarnes, mburns, mdellweg, mgarciac, mhulan, mminar, nboldt, nmoumoul, oaljalju, oezr, orabin, osousa, pantinor, pcreech, ppalepu, ppostler, prdhamdh, psrna, rbiba, rblanco, rchan, rekumar, rhel-process-autobot, rjohnson, rojacob, sarad, sghai, sidsharm, simaishi, smallamp, sprizend, sskracic, stcannon, suppawar, teagle, tmalecek, tpfromme, tsedmik, vlaad, vvoronko, watson-tool-maintainers, weaton, xiaoxwan, yguenane, ykashtan, zzhou
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packets, fails to properly validate string-carrying extensions for null-termination. This oversight allows a remote attacker to craft a malicious packet, leading to an out-of-bounds read when the packet's payload is processed. Successful exploitation of this vulnerability could result in the disclosure of sensitive information or a remote denial of service (DoS).
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2514692, 2514697    
Bug Blocks:    

Description OSIDB Bzimport 2026-09-17 12:20:34 UTC
In Redis community the cluster bus PING/PONG/MEET packet parser validated extension padding
and total length but never checked that string-carrying extensions are
properly null-terminated, allowing a crafted packet to trigger
out-of-bounds reads when the payload is later consumed as a C string. This vulnerability can potentially lead to loss of confidentiality or remote denial of service. Redis Software / Redis Enterprise are not affected by this issue.

Comment 2 Jon Orris 2026-09-21 16:14:21 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:69521 https://access.redhat.com/errata/RHSA-2026:69521

Comment 3 Jon Orris 2026-09-21 16:43:27 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:69520 https://access.redhat.com/errata/RHSA-2026:69520