Description
A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packets, fails to properly validate string-carrying extensions for null-termination. This oversight allows a remote attacker to craft a malicious packet, leading to an out-of-bounds read when the packet's payload is processed. Successful exploitation of this vulnerability could result in the disclosure of sensitive information or a remote denial of service (DoS).
Published: 2026-09-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-bounds read in the Redis cluster bus packet parser enabling information disclosure or denial of service
Action: Apply Patch
AI Analysis

Impact

A flaw in Redis now allows a remote attacker to craft a malicious cluster bus packet that bypasses string-carrying extension validation, resulting in an out-of-bounds read. The code that processes the packet’s payload does not verify proper null termination, which can expose memory contents to the attacker or, if the read overruns and corrupts critical state, trigger a remote denial of service. The weakness is classified as CWE‑125, a classic unvalidated read of memory.

Affected Systems

The vulnerability affects a broad range of Red Hat products that embed or depend on Redis, including the AI inference server, the Ansible Automation Platform, the Confidential Compute Attestation service, the Connectivity Link, the Enterprise Linux AI distribution, the Logging subsystem, the OpenShift platform and AI stack, the update service, multiple OpenStack Platform releases, the PDrive Lightspeed module, Quay, the 3scale API Management Platform, the Red Hat Developer Hub, the update infrastructure and the Satellite management system.

Risk and Exploitability

The CVSS score of 7.1 indicates a high risk to confidentiality and availability, while the EPSS score is not available and the issue is not listed in the CISA KEV catalog. The likely attack vector is remote over the network by sending a crafted packet to the Redis cluster bus interface, which is typically accessible on port 6379 or a cluster‑specific port. An attacker with network access to the cluster can trigger the read, potentially causing information leakage or a service disruption without requiring local privileges.

Generated by OpenCVE AI on September 17, 2026 at 21:49 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.


OpenCVE Recommended Actions

  • Upgrade Redis to version 8.10.0 or later, which includes the packet parser fix, in all Red Hat products that embed Redis
  • Restart the affected services or disable and re‑enable the Redis cluster bus interface to ensure the updated code is active
  • Restrict network access to the Redis cluster bus port using firewalls or tenant isolation, limiting exposure only to trusted nodes or control planes

Generated by OpenCVE AI on September 17, 2026 at 21:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4794-1 redis security update
History

Tue, 22 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:enterprise_linux:9::appstream
References

Mon, 21 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhel Eus
CPEs cpe:/a:redhat:rhel_eus:9.6::appstream
Vendors & Products Redhat rhel Eus
References

Mon, 21 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhel E4s
CPEs cpe:/a:redhat:rhel_e4s:9.4::appstream
Vendors & Products Redhat rhel E4s
References

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Red Hat
Red Hat pen Drive Powered By Red Hat Lightspeed
Red Hat red Hat Openshift Ai (rhoai)
Redhat 3scale Api Management Platform
Redhat ai Inference Server
Redhat ansible Automation Platform
Redhat confidential Compute Attestation
Redhat connectivity Link
Redhat enterprise Linux Ai
Redhat logging Subsystem For Red Hat Openshift
Redhat openshift Container Platform
Redhat openshift Update Service
Redhat openstack Platform
Redhat quay 3
Redhat red Hat Developer Hub
Redhat satellite 6
Redhat update Infrastructure
Vendors & Products Red Hat
Red Hat pen Drive Powered By Red Hat Lightspeed
Red Hat red Hat Openshift Ai (rhoai)
Redhat 3scale Api Management Platform
Redhat ai Inference Server
Redhat ansible Automation Platform
Redhat confidential Compute Attestation
Redhat connectivity Link
Redhat enterprise Linux Ai
Redhat logging Subsystem For Red Hat Openshift
Redhat openshift Container Platform
Redhat openshift Update Service
Redhat openstack Platform
Redhat quay 3
Redhat red Hat Developer Hub
Redhat satellite 6
Redhat update Infrastructure

Fri, 18 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat enterprise Linux
Redhat hummingbird
CPEs cpe:/a:redhat:hummingbird:1
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat enterprise Linux
Redhat hummingbird

Fri, 18 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openstack:18.0
cpe:/a:redhat:rhui:5::el9
Vendors & Products Redhat openstack
Redhat rhui

Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Fri, 18 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:ai_inference_server:3
cpe:/a:redhat:ansible_automation_platform:2
cpe:/a:redhat:confidential_compute_attestation:1
cpe:/a:redhat:connectivity_link:1
cpe:/a:redhat:enterprise_linux_ai:3
cpe:/a:redhat:logging:6
cpe:/a:redhat:openshift:4
cpe:/a:redhat:openshift_ai
cpe:/a:redhat:openshift_update_service:5
cpe:/a:redhat:openstack:16.2
cpe:/a:redhat:openstack:17.1
cpe:/a:redhat:quay:3
cpe:/a:redhat:rhdh:1
cpe:/a:redhat:satellite:6
Vendors & Products Redhat ai Inference Server
Redhat ansible Automation Platform
Redhat confidential Compute Attestation
Redhat connectivity Link
Redhat enterprise Linux Ai
Redhat logging
Redhat openshift
Redhat openshift Ai
Redhat openshift Update Service
Redhat quay
Redhat rhdh
Redhat satellite

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV4_0

{'score': 6.0, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In Redis community the cluster bus PING/PONG/MEET packet parser validated extension padding and total length but never checked that string-carrying extensions are properly null-terminated, allowing a crafted packet to trigger out-of-bounds reads when the payload is later consumed as a C string. This vulnerability can potentially lead to loss of confidentiality or remote denial of service. Redis Software / Redis Enterprise are not affected by this issue. A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packets, fails to properly validate string-carrying extensions for null-termination. This oversight allows a remote attacker to craft a malicious packet, leading to an out-of-bounds read when the packet's payload is processed. Successful exploitation of this vulnerability could result in the disclosure of sensitive information or a remote denial of service (DoS).
Title Out-of-Bounds Read in Cluster Bus Redis: redis: out-of-bounds read via crafted cluster bus packets
First Time appeared Redhat
Redhat ai Inference Server
Redhat ansible Automation Platform
Redhat confidential Compute Attestation
Redhat connectivity Link
Redhat enterprise Linux Ai
Redhat logging
Redhat openshift
Redhat openshift Ai
Redhat openshift Update Service
Redhat openstack
Redhat pdrive Lightspeed
Redhat quay
Redhat red Hat 3scale Amp
Redhat rhdh
Redhat rhui
Redhat satellite
CPEs cpe:/a:redhat:ai_inference_server:3
cpe:/a:redhat:ansible_automation_platform:2
cpe:/a:redhat:confidential_compute_attestation:1
cpe:/a:redhat:connectivity_link:1
cpe:/a:redhat:enterprise_linux_ai:3
cpe:/a:redhat:logging:6
cpe:/a:redhat:openshift:4
cpe:/a:redhat:openshift_ai
cpe:/a:redhat:openshift_update_service:5
cpe:/a:redhat:openstack:16.2
cpe:/a:redhat:openstack:17.1
cpe:/a:redhat:openstack:18.0
cpe:/a:redhat:pdrive_lightspeed:1
cpe:/a:redhat:quay:3
cpe:/a:redhat:red_hat_3scale_amp:2
cpe:/a:redhat:rhdh:1
cpe:/a:redhat:rhui:5::el9
cpe:/a:redhat:satellite:6
Vendors & Products Redhat
Redhat ai Inference Server
Redhat ansible Automation Platform
Redhat confidential Compute Attestation
Redhat connectivity Link
Redhat enterprise Linux Ai
Redhat logging
Redhat openshift
Redhat openshift Ai
Redhat openshift Update Service
Redhat openstack
Redhat pdrive Lightspeed
Redhat quay
Redhat red Hat 3scale Amp
Redhat rhdh
Redhat rhui
Redhat satellite
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N'}

cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H'}

cvssV4_0

{'score': 6.0, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X'}


Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Description In Redis community the cluster bus PING/PONG/MEET packet parser validated extension padding and total length but never checked that string-carrying extensions are properly null-terminated, allowing a crafted packet to trigger out-of-bounds reads when the payload is later consumed as a C string. This vulnerability can potentially lead to loss of confidentiality or remote denial of service. Redis Software / Redis Enterprise are not affected by this issue.
Title Out-of-Bounds Read in Cluster Bus
Weaknesses CWE-125
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Red Hat Pen Drive Powered By Red Hat Lightspeed Red Hat Openshift Ai (rhoai)
Redhat 3scale Api Management Platform Ai Inference Server Ansible Automation Platform Confidential Compute Attestation Connectivity Link Enterprise Linux Enterprise Linux Ai Hummingbird Logging Subsystem For Red Hat Openshift Openshift Container Platform Openshift Update Service Openstack Platform Pdrive Lightspeed Quay 3 Red Hat 3scale Amp Red Hat Developer Hub Rhel E4s Rhel Eus Satellite 6 Update Infrastructure
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-22T18:55:42.473Z

Reserved: 2026-09-17T11:31:08.832Z

Link: CVE-2026-92925

cve-icon Vulnrichment

Updated: 2026-09-17T14:24:06.846Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T12:18:31.063

Modified: 2026-09-22T19:16:57.127

Link: CVE-2026-92925

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-17T11:48:04Z

Links: CVE-2026-92925 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:37:34Z

Weaknesses