CVE-2026-92925

HIGHCVSS 7.1/10

Last modified

CVE-2026-92925 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packets, fails to properly validate string-carrying extensions for null-termination.

Description

A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packets, fails to properly validate string-carrying extensions for null-termination. This oversight allows a remote attacker to craft a malicious packet, leading to an out-of-bounds read when the packet's payload is processed. Successful exploitation of this vulnerability could result in the disclosure of sensitive information or a remote denial of service (DoS).

Metrics

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
Red HatPen Drive Powered by Red Hat LightspeedAll versions
Red HatRed Hat 3scale API Management Platform 2All versions
Red HatRed Hat Enterprise Linux 9All versions
Red HatRed Hat Hardened ImagesAll versions

References

Timeline

Published
Last Modified
Status
Awaiting Analysis

Frequently Asked Questions

What is CVE-2026-92925?
A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packets, fails to properly validate string-carrying extensions for null-termination. This oversight allows a remote attacker to craft a malicious packet, leading to an out-of-bounds read when the packet's payload is processed. Successful exploitation of this vulnerability could result in the disclosure of sensitive information or a remote denial of service (DoS).
How severe is CVE-2026-92925?
CVE-2026-92925 has a CVSS score of 7.1/10 (HIGH severity).
How do I fix CVE-2026-92925?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-92925?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST