{"id":"USN-8866-1","summary":"redis vulnerabilities","details":"It was discovered that Redis did not properly manage memory when handling\nthe TLS pending-data list. A remote attacker could possibly use this issue\nto execute arbitrary code. (CVE-2026-81934)\n\nIt was discovered that Redis incorrectly handled certain inputs when\nprocessing cluster bus packets. A remote attacker could possibly use this\nissue to expose sensitive information or cause a denial of service. This\nissue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-92925)","modified":"2026-10-08T12:58:04.578061557Z","published":"2026-10-06T03:02:05Z","related":["UBUNTU-CVE-2026-81934","UBUNTU-CVE-2026-92925"],"upstream":["CVE-2026-81934","CVE-2026-92925","UBUNTU-CVE-2026-81934","UBUNTU-CVE-2026-92925"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8866-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-81934"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-92925"}],"affected":[{"package":{"name":"redis","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/redis?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5:6.0.16-1ubuntu1.2"}]}],"versions":["5:6.0.15-1","5:6.0.16-1","5:6.0.16-1build1","5:6.0.16-1ubuntu1","5:6.0.16-1ubuntu1.1"],"ecosystem_specific":{"binaries":[{"binary_version":"5:6.0.16-1ubuntu1.2","binary_name":"redis"},{"binary_version":"5:6.0.16-1ubuntu1.2","binary_name":"redis-sentinel"},{"binary_version":"5:6.0.16-1ubuntu1.2","binary_name":"redis-server"},{"binary_name":"redis-tools","binary_version":"5:6.0.16-1ubuntu1.2"}],"availability":"No subscription required"},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:22.04:LTS","cves":[{"id":"CVE-2026-81934","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:A/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}]}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8866-1.json"}},{"package":{"name":"redis","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/redis?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5:7.0.15-1ubuntu0.24.04.5"}]}],"versions":["5:7.0.12-1","5:7.0.14-1","5:7.0.14-2","5:7.0.15-1","5:7.0.15-1build1","5:7.0.15-1build2","5:7.0.15-1ubuntu0.24.04.1","5:7.0.15-1ubuntu0.24.04.2","5:7.0.15-1ubuntu0.24.04.3","5:7.0.15-1ubuntu0.24.04.4"],"ecosystem_specific":{"binaries":[{"binary_name":"redis","binary_version":"5:7.0.15-1ubuntu0.24.04.5"},{"binary_name":"redis-sentinel","binary_version":"5:7.0.15-1ubuntu0.24.04.5"},{"binary_name":"redis-server","binary_version":"5:7.0.15-1ubuntu0.24.04.5"},{"binary_name":"redis-tools","binary_version":"5:7.0.15-1ubuntu0.24.04.5"}],"availability":"No subscription required"},"database_specific":{"cves_map":{"cves":[{"id":"CVE-2026-81934","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"score":"CVSS:4.0/AV:A/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","type":"CVSS_V4"},{"type":"Ubuntu","score":"medium"}]},{"severity":[{"score":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-92925"}],"ecosystem":"Ubuntu:24.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8866-1.json"}},{"package":{"name":"redis","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/redis?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5:8.0.5-1ubuntu0.1"}]}],"versions":["5:8.0.2-3build1","5:8.0.2-3ubuntu0.25.10.1","5:8.0.5-1"],"ecosystem_specific":{"binaries":[{"binary_version":"5:8.0.5-1ubuntu0.1","binary_name":"redis"},{"binary_name":"redis-sentinel","binary_version":"5:8.0.5-1ubuntu0.1"},{"binary_name":"redis-server","binary_version":"5:8.0.5-1ubuntu0.1"},{"binary_version":"5:8.0.5-1ubuntu0.1","binary_name":"redis-tools"}],"availability":"No subscription required"},"database_specific":{"cves_map":{"cves":[{"id":"CVE-2026-81934","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:A/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-92925","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]}],"ecosystem":"Ubuntu:26.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8866-1.json"}}],"schema_version":"1.9.0"}