redis-server use-after-free in unblock client flow may allow remote code execution (CVE-2026-23479)
Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated attacker can trigger a use-after-free that may lead to remote code execution. This has been patched in version 8.6.3.
AI Analysis
Technical Summary
This security advisory addresses a use-after-free vulnerability (CWE-416) in Redis server related to Lua scripting during master-replica synchronization. The flaw occurs when replicas have the replica-read-only setting disabled or can be disabled by an authenticated attacker, enabling exploitation that may lead to remote code execution. The vulnerability impacts Redis instances configured for write operations on replicas or with insufficient access control to prevent modification of replica-read-only. The advisory recommends maintaining replica-read-only enabled, disabling Lua scripting if unnecessary, and restricting network access to trusted clients. Red Hat provides updated Boost RPM packages as part of the Hardened Images update, but the advisory does not explicitly confirm a patch for Redis itself. The CVSS score is not provided, but the vulnerability is rated as high severity by Red Hat.
Potential Impact
Successful exploitation of this use-after-free vulnerability can lead to remote code execution on Redis replicas that have replica-read-only disabled or modifiable by an attacker with authentication. This could compromise confidentiality, integrity, and availability of the affected Redis service. The impact includes potential unauthorized code execution, data corruption, and service disruption. The vulnerability requires low attacker privileges and no user interaction, increasing risk in improperly configured environments.
Mitigation Recommendations
Red Hat's advisory recommends ensuring that Redis replicas have the replica-read-only setting enabled and that unauthorized users cannot modify this setting. If Lua scripting is not required, it should be disabled to reduce the attack surface. Additionally, network access to Redis instances should be restricted to trusted clients only. Configuration changes require restarting the Redis service, which will cause temporary service interruption. Patch status for Redis in Red Hat products is not explicitly confirmed; therefore, users should monitor Red Hat advisories for official fixes and apply recommended configuration mitigations in the meantime.
redis-server use-after-free in unblock client flow may allow remote code execution (CVE-2026-23479)
Description
Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated attacker can trigger a use-after-free that may lead to remote code execution. This has been patched in version 8.6.3.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This security advisory addresses a use-after-free vulnerability (CWE-416) in Redis server related to Lua scripting during master-replica synchronization. The flaw occurs when replicas have the replica-read-only setting disabled or can be disabled by an authenticated attacker, enabling exploitation that may lead to remote code execution. The vulnerability impacts Redis instances configured for write operations on replicas or with insufficient access control to prevent modification of replica-read-only. The advisory recommends maintaining replica-read-only enabled, disabling Lua scripting if unnecessary, and restricting network access to trusted clients. Red Hat provides updated Boost RPM packages as part of the Hardened Images update, but the advisory does not explicitly confirm a patch for Redis itself. The CVSS score is not provided, but the vulnerability is rated as high severity by Red Hat.
Potential Impact
Successful exploitation of this use-after-free vulnerability can lead to remote code execution on Redis replicas that have replica-read-only disabled or modifiable by an attacker with authentication. This could compromise confidentiality, integrity, and availability of the affected Redis service. The impact includes potential unauthorized code execution, data corruption, and service disruption. The vulnerability requires low attacker privileges and no user interaction, increasing risk in improperly configured environments.
Mitigation Recommendations
Red Hat's advisory recommends ensuring that Redis replicas have the replica-read-only setting enabled and that unauthorized users cannot modify this setting. If Lua scripting is not required, it should be disabled to reduce the attack surface. Additionally, network access to Redis instances should be restricted to trusted clients only. Configuration changes require restarting the Redis service, which will cause temporary service interruption. Patch status for Redis in Red Hat products is not explicitly confirmed; therefore, users should monitor Red Hat advisories for official fixes and apply recommended configuration mitigations in the meantime.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_vex
- Csaf Version
- 2.0
- Publisher
- Microsoft Security Response Center
- Advisory Id
- msrc_CVE-2026-23479
- Cve Count
- 1
Threat ID: 6a209840e29bf47b50ebe7b0
Added to database: 06/03/2026, 21:10:24 UTC
Last enriched: 08/16/2026, 17:39:21 UTC
Last updated: 09/12/2026, 12:14:27 UTC
Views: 123
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.