CVE-2026-92925

Publication date 17 September 2026

Last updated 8 October 2026


Ubuntu priority

Cvss 3 Severity Score

7.1 · High

Score breakdown

Description

A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packets, fails to properly validate string-carrying extensions for null-termination. This oversight allows a remote attacker to craft a malicious packet, leading to an out-of-bounds read when the packet's payload is processed. Successful exploitation of this vulnerability could result in the disclosure of sensitive information or a remote denial of service (DoS).

Status

Package Ubuntu Release Status
redis 26.04 LTS resolute
Fixed 5:8.0.5-1ubuntu0.1
24.04 LTS noble
Fixed 5:7.0.15-1ubuntu0.24.04.5
22.04 LTS jammy
Not affected
20.04 LTS focal
Not affected
18.04 LTS bionic
Not affected
16.04 LTS xenial
Not affected
14.04 LTS trusty
Not affected

Severity score breakdown

CVSS version: CVSS v3.0

Base score 7.1 · High

Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

References

Related Ubuntu Security Notices (USN)

Other references


Access our resources on patching vulnerabilities