A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packets, fails to properly validate string-carrying extensions for null-termination. This oversight allows a remote attacker to craft a malicious packet, leading to an out-of-bounds read when the packet's payload is processed. Successful exploitation of this vulnerability could result in the disclosure of sensitive information or a remote denial of service (DoS).
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV4_0

{'score': 6.0, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In Redis community the cluster bus PING/PONG/MEET packet parser validated extension padding and total length but never checked that string-carrying extensions are properly null-terminated, allowing a crafted packet to trigger out-of-bounds reads when the payload is later consumed as a C string. This vulnerability can potentially lead to loss of confidentiality or remote denial of service. Redis Software / Redis Enterprise are not affected by this issue. A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packets, fails to properly validate string-carrying extensions for null-termination. This oversight allows a remote attacker to craft a malicious packet, leading to an out-of-bounds read when the packet's payload is processed. Successful exploitation of this vulnerability could result in the disclosure of sensitive information or a remote denial of service (DoS).
Title Out-of-Bounds Read in Cluster Bus Redis: redis: out-of-bounds read via crafted cluster bus packets
First Time appeared Redhat
Redhat ai Inference Server
Redhat ansible Automation Platform
Redhat confidential Compute Attestation
Redhat connectivity Link
Redhat enterprise Linux Ai
Redhat logging
Redhat openshift
Redhat openshift Ai
Redhat openshift Update Service
Redhat openstack
Redhat pdrive Lightspeed
Redhat quay
Redhat red Hat 3scale Amp
Redhat rhdh
Redhat rhui
Redhat satellite
CPEs cpe:/a:redhat:ai_inference_server:3
cpe:/a:redhat:ansible_automation_platform:2
cpe:/a:redhat:confidential_compute_attestation:1
cpe:/a:redhat:connectivity_link:1
cpe:/a:redhat:enterprise_linux_ai:3
cpe:/a:redhat:logging:6
cpe:/a:redhat:openshift:4
cpe:/a:redhat:openshift_ai
cpe:/a:redhat:openshift_update_service:5
cpe:/a:redhat:openstack:16.2
cpe:/a:redhat:openstack:17.1
cpe:/a:redhat:openstack:18.0
cpe:/a:redhat:pdrive_lightspeed:1
cpe:/a:redhat:quay:3
cpe:/a:redhat:red_hat_3scale_amp:2
cpe:/a:redhat:rhdh:1
cpe:/a:redhat:rhui:5::el9
cpe:/a:redhat:satellite:6
Vendors & Products Redhat
Redhat ai Inference Server
Redhat ansible Automation Platform
Redhat confidential Compute Attestation
Redhat connectivity Link
Redhat enterprise Linux Ai
Redhat logging
Redhat openshift
Redhat openshift Ai
Redhat openshift Update Service
Redhat openstack
Redhat pdrive Lightspeed
Redhat quay
Redhat red Hat 3scale Amp
Redhat rhdh
Redhat rhui
Redhat satellite
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N'}

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H'}

cvssV4_0

{'score': 6.0, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X'}


Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Description In Redis community the cluster bus PING/PONG/MEET packet parser validated extension padding and total length but never checked that string-carrying extensions are properly null-terminated, allowing a crafted packet to trigger out-of-bounds reads when the payload is later consumed as a C string. This vulnerability can potentially lead to loss of confidentiality or remote denial of service. Redis Software / Redis Enterprise are not affected by this issue.
Title Out-of-Bounds Read in Cluster Bus
Weaknesses CWE-125
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-17T16:25:38.784Z

Reserved: 2026-09-17T11:31:08.832Z

Link: CVE-2026-92925

cve-icon Vulnrichment

Updated: 2026-09-17T14:24:06.846Z

cve-icon NVD

Status : Received

Published: 2026-09-17T12:18:31.063

Modified: 2026-09-17T17:17:55.913

Link: CVE-2026-92925

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses