Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by mo…
Summary
Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting both consumers via XGROUP DELCONSUMER leads to a double free. NOTE: this issue exists because of an incomplete fix for CVE-2026-25243.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Lint boundary warnings (2)
The following non-blocking warnings were raised during the lint phase of this triage (e.g. reference URLs not yet on the allowlist). They do not affect entry usability and are disclosed for transparency (see DR-002).
-
REF_URL_NOT_ALLOWLISTEDurl not in allowlist: https://news.ycombinator.com/item?id=49024938 -
REF_URL_NOT_ALLOWLISTEDurl not in allowlist: https://x.com/Fried_rice/status/2080059356322918777
Sources
- NVD DATABASE
CH-4 Twitter/X Fair-Use Reference
This reference follows the DR-006 + DR-008 fair-use boundary: ≤280-char verbatim quote, mandatory @attribution, mandatory outbound link. No account mirroring and no third-party tracker widget loaded.
Original author
Read tweet ↗ · Tweets may be deleted or accounts suspended; see the R2 archive if the original is unreachable.
Original Links
- https://github.com/berabuddies/redis-poc
- https://github.com/redis/redis/compare/8.6.4...8.8.0
- https://github.com/redis/redis/pull/15081
- https://news.ycombinator.com/item?id=49024938
- https://x.com/Fried_rice/status/2080059356322918777
- https://github.com/berabuddies/redis-poc
Timeline
- nvd_ingest NVD