#1147422 redis: CVE-2026-66373

Package:
redis
Source:
redis
Submitter:
Moritz Mühlenhoff
Date:
2026-09-12 19:33:02 UTC
Severity:
normal
Tags:
#1147422#5
Date:
2026-09-11 17:00:58 UTC
From:
To:
Hi,

The following vulnerability was published for important.

CVE-2026-66373[0]:
| Redis before 8.8.0, in the unusual case where an authenticated
| attacker can execute RESTORE, allows remote code execution via a
| RESTORE payload where the same NACK (pending entry) is referenced by
| more than one consumer, because deleting both consumers via XGROUP
| DELCONSUMER leads to a double free. NOTE: this issue exists because
| of an incomplete fix for CVE-2026-25243.

Fixed by: https://github.com/redis/redis/commit/4f62a8bf15c634187d8a87d874f8988032f90b6c (8.6.5)
Fixed by: https://github.com/redis/redis/commit/04292292f2f5c180322292007a599a700611ebaf (7.2.15)
fixed by: https://github.com/redis/redis/commit/41a958720e64e03576dd652d224aa46d22c096c3 (6.2.23)

Issue exists because of an incomplete fix for CVE-2026-25243.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-66373
https://www.cve.org/CVERecord?id=CVE-2026-66373

Please adjust the affected versions in the BTS as needed.