Skip to main content

Threats Tagged 'cve-2026-62356'

View all threats tagged with 'cve-2026-62356'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-62356

Threats Tagged 'cve-2026-62356'

Click on any threat for detailed analysis and mitigation recommendations

0

This update for redis fixes the following issues: Changes in redis: - Update to 8.10.1 Update urgency: SECURITY: There are security fixes in the release. - Security fixes - (CVE-2026-62356) Miscalculated buffer size in CMSketch RDB loading may lead to heap OOB write - Out-of-bounds access in TopK heap cleanup path (MOD-15410) - Use-after-free in the TLS pending-data list when a command closes another pending connection - A malicious RDB payload with an out-of-range SLOT_INFO slot id causes memory corruption during RDB loading, which may lead to Remote Code Execution - Vector Sets: missing node level validation when loading a vector set from RDB may lead to out-of-bounds access - Vector Sets: use-after-free when VREM mutates the HNSW graph while background VSIM threads are still running - Vector Sets: a negative hnsw_search() return was treated as a huge unsigned count, reading past the end of the result arrays - TLS client certificate authentication bypass: a Common Name containing an embedded NUL byte was truncated, allowing a client to authenticate as another (possibly privileged) ACL user - #15594 Use-after-free in the blocked-client list when reprocessing a command evicts another client blocked on the same key - Restrict the "modules" flavour to x86_64 and aarch64 -- RedisBloom and RedisTimeSeries abort on anything else with "only supports 64-bit architectures (x64, arm64v8)", redisjson's vendored redis-module is 64-bit only, and modules/common.mk maps no other architecture at all - Update to 8.10.0 Major changes compared to 8.8 - Compact hashes - a new hash encoding that reduces memory usage by storing hash field names just once for keys that share a schema - New command: HIMPORT - high-throughput compact hash bulk insertion - TLS peer certificate-based server-to-server authentication - New commands: LMOVEM, BLMOVEM - move multiple elements between lists - New command: SUNIONCARD - get the cardinality of the union of multiple sets - New command: SDIFFCARD - get the cardinality of the difference between sets - New command: BACKUP - node-side implementation for backup and restore based on multi-part AOF (MP-AOF) - XREAD, XREADGROUP - new MAXCOUNT and MAXSIZE arguments to cap the cumulative reply entries and size - New command: FT.ALIASLIST - get all aliases for the index - Stemmer support for Malay and Tagalog languages - JSONPath extensions - New commands: TS.NRANGE, TS.NREVRANGE - Query a range across multiple time series; group results by timestamp - New command: TS.READ - optionally blocking read - New command: TS.QUERYLABELS - Get a list of labels and label-values - New command: TS.MRANGE, TS.MREVRANGE - new EXCLUDEEMPTY argument to exclude series with no reported samples - Performance improvements - Update to 8.8.1 Security fixes - RedisBloom/RedisBloom#1044 Crafted RESTORE payloads in RedisBloom and TDigest may trigger out-of-bounds writes, potentially leading to remote code execution - Update to 8.8.0 - New data structure: Array (@antirez) - Subkey notification for hash fields - field-level notifications - INCREX: a window counter rate limiter combining INCR, INCRBY, INCRBYFLOAT, bounds, and expiration (@raffertyyu + Redis team) - XNACK: a new streams command - allow consumers to explicitly release pending messages - ZUNION, ZINTER, ZUNIONSTORE, ZINTERSTORE: new COUNT aggregator - JSON.SET: new FPHA argument to specify the FP type for homogeneous FP arrays - TS.RANGE, TS.REVRANGE, TS.MRANGE, TS.MREVRANGE: multiple aggregators in a single command - FT.HYBRID KNN clause: new argument to request fewer candidates per shard - FT.PROFILE HYBRID: profiling support for FT.HYBRID - Performance improvements - Updated to 8.6.3 (boo#1264164 boo#1264165 boo#1264166 boo#1264167 boo#1264168) - Security fixes - (CVE-2026-23479) Use-After-Free in unblock client flow may lead to Remote Code Execution. - (CVE-2026-25243) Invalid memory access in RESTORE may lead to Remote Code Execution - (CVE-2026-23631) Lua Use-After-Free may lead to remote code execution - (CVE-2026-25588) Invalid memory access in RESTORE may lead to Remote Code Execution (Time Series) - (CVE-2026-25589) Invalid memory access in RESTORE may lead to Remote Code Execution (Probabilistic) - Bug fixes - SUBSCRIBE, PSUBSCRIBE, SSUBSCRIBE: crash on OOM (RED-167788) - CONFIG SET: some settings allow invalid characters (RED-167787) - SCRIPT DEBUG: potential crash on scripts (RED-175507) - VADD: crash or buffer overflow on large REDUCE value (RED-170921) - VSET: crash on huge allocations (MOD-12678) - Potential crash on disconnections and TLS failures (Time Series) (MOD-14850) - RediSearch/RediSea

Join the discussion
0

Multiple security issues were fixed in the redis-8.10.1-1.1 package distributed with openSUSE Tumbleweed. The vulnerabilities addressed are related to the SUSE Redis package version 8.10.1-1.1. No specific details about the nature of the vulnerabilities or affected versions are provided.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: cve-2026-62356
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses