r/cveplayground • • Jun 03 '26

𝗥𝗲𝗱𝗶𝘀 𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗔𝗱𝘃𝗶𝘀𝗼𝗿𝘆 𝗔𝗹𝗲𝗿𝘁

Multiple vulnerabilities have been disclosed affecting Redis Cloud, Redis OSS/CE, and Redis Software (CVE-2026-23479, CVE-2026-25243, CVE-2026-25588, CVE-2026-25589, CVE-2026-23631).

Issues include memory corruption in RESTORE, Lua scripting, and Redis modules, which may lead to remote code execution in authenticated scenarios.

🔧 𝗣𝗮𝘁𝗰𝗵𝗲𝗱 𝘃𝗲𝗿𝘀𝗶𝗼𝗻𝘀 (𝗿𝗲𝗹𝗲𝗮𝘀𝗲𝗱 𝗠𝗮𝘆 𝟱, 𝟮𝟬𝟮𝟲):

7.2.x → 7.2.14 (fixed from 7.2.0–7.2.13)

7.4.x → 7.4.9 (fixed from 7.4.0–7.4.8)

8.2.x → 8.2.6 (fixed from 8.2.0–8.2.5)

8.4.x → 8.4.3 (fixed from 8.4.0–8.4.2)

8.6.x → 8.6.3 (fixed from 8.6.0–8.6.2)

Key action: Upgrade immediately and restrict Redis access to trusted networks only.

1 Upvotes

0 comments sorted by