Impact
A flaw in Redis now allows a remote attacker to craft a malicious cluster bus packet that bypasses string-carrying extension validation, resulting in an out-of-bounds read. The code that processes the packet’s payload does not verify proper null termination, which can expose memory contents to the attacker or, if the read overruns and corrupts critical state, trigger a remote denial of service. The weakness is classified as CWE‑125, a classic unvalidated read of memory.
Affected Systems
The vulnerability affects a broad range of Red Hat products that embed or depend on Redis, including the AI inference server, the Ansible Automation Platform, the Confidential Compute Attestation service, the Connectivity Link, the Enterprise Linux AI distribution, the Logging subsystem, the OpenShift platform and AI stack, the update service, multiple OpenStack Platform releases, the PDrive Lightspeed module, Quay, the 3scale API Management Platform, the Red Hat Developer Hub, the update infrastructure and the Satellite management system.
Risk and Exploitability
The CVSS score of 7.1 indicates a high risk to confidentiality and availability, while the EPSS score is not available and the issue is not listed in the CISA KEV catalog. The likely attack vector is remote over the network by sending a crafted packet to the Redis cluster bus interface, which is typically accessible on port 6379 or a cluster‑specific port. An attacker with network access to the cluster can trigger the read, potentially causing information leakage or a service disruption without requiring local privileges.
OpenCVE Enrichment
Debian DLA