Source: important
X-Debbugs-CC: [email protected]
Severity: grave
Tags: security

Hi,

The following vulnerability was published for important.

CVE-2026-66373[0]:
| Redis before 8.8.0, in the unusual case where an authenticated
| attacker can execute RESTORE, allows remote code execution via a
| RESTORE payload where the same NACK (pending entry) is referenced by
| more than one consumer, because deleting both consumers via XGROUP
| DELCONSUMER leads to a double free. NOTE: this issue exists because
| of an incomplete fix for CVE-2026-25243.

Fixed by: 
https://github.com/redis/redis/commit/4f62a8bf15c634187d8a87d874f8988032f90b6c 
(8.6.5)
Fixed by: 
https://github.com/redis/redis/commit/04292292f2f5c180322292007a599a700611ebaf 
(7.2.15)
fixed by: 
https://github.com/redis/redis/commit/41a958720e64e03576dd652d224aa46d22c096c3 
(6.2.23)

Issue exists because of an incomplete fix for CVE-2026-25243.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-66373
    https://www.cve.org/CVERecord?id=CVE-2026-66373

Please adjust the affected versions in the BTS as needed.

Reply via email to