{"id":"CVE-2026-92925","summary":"Redis: redis: out-of-bounds read via crafted cluster bus packets","details":"A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packets, fails to properly validate string-carrying extensions for null-termination. This oversight allows a remote attacker to craft a malicious packet, leading to an out-of-bounds read when the packet's payload is processed. Successful exploitation of this vulnerability could result in the disclosure of sensitive information or a remote denial of service (DoS).","modified":"2026-09-20T14:16:39.280111Z","published":"2026-09-17T11:48:04.664Z","database_specific":{"cna_assigner":"redhat","cwe_ids":["CWE-125"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92925.json"},"references":[{"type":"WEB","url":"https://access.redhat.com/downloads/content/package-browser/"},{"type":"WEB","url":"https://github.com/redis/redis/releases/tag/8.10.0"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-92925"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92925.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92925"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2535971"},{"type":"FIX","url":"https://github.com/redis/redis/commit/37894faeea11e2db28b9fc2af378a762d2c36523"},{"type":"FIX","url":"https://github.com/redis/redis/pull/15263"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/redis/redis","events":[{"introduced":"0"},{"fixed":"37894faeea11e2db28b9fc2af378a762d2c36523"},{"fixed":"5279a8d44818a5ca51e9abb91a9b8ce481d3c88b"}],"database_specific":{"source":"REFERENCES"}}],"versions":["8.10-rc2","8.10-rc1","8.10-m04-int","8.10-m03-int","8.10-m02-int","8.10-m01-int","8.4-int","2.3-alpha0","2.2.0-rc1","2.2-alpha6","2.2-alpha5","2.2-alpha4","2.2-alpha3","2.2-alpha2","2.2-alpha1","2.2-alpha0","v2.0.0-rc1","v2.1.1-watch","v1.3.11","v1.3.10","v1.3.9","v1.3.8","v1.3.7","1.3.6","vm-playpen"],"database_specific":{"vanir_signatures":[{"signature_version":"v1","source":"https://github.com/redis/redis/commit/37894faeea11e2db28b9fc2af378a762d2c36523","target":{"file":"src/cluster_legacy.c"},"deprecated":false,"digest":{"line_hashes":["13279014130636900447888149085080901188","66450121725317823420902280751939412249","94100035610033848263607306682728551612","116644692456477797365927837214807213373","127024583072053186129462409419977113981","89149673714987742241634026751059035615","31285712546404403212188135398719013128","239689532422510736080321087532888670017","99878103810376704475268591093493230626","97737256664382199430702003548256822764","91259257128675313053010695061663281647","205500128442031084785654296787376237943"],"threshold":0.9},"id":"CVE-2026-92925-5d0a7e6b","signature_type":"Line"},{"target":{"file":"src/cluster_legacy.c","function":"auxShardIdPresent"},"deprecated":false,"digest":{"function_hash":"230046582170578232748377566269448724473","length":76},"id":"CVE-2026-92925-6ba0679e","signature_type":"Function","signature_version":"v1","source":"https://github.com/redis/redis/commit/37894faeea11e2db28b9fc2af378a762d2c36523"},{"source":"https://github.com/redis/redis/commit/37894faeea11e2db28b9fc2af378a762d2c36523","target":{"file":"src/cluster_legacy.c","function":"clusterProcessPacket"},"deprecated":false,"digest":{"function_hash":"145298396018917868586487560831436167436","length":13693},"id":"CVE-2026-92925-ff566eb3","signature_type":"Function","signature_version":"v1"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92925.json","vanir_signatures_modified":"2026-09-20T14:16:39Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"}]}