← Back
Database / Storage
CVE-2026-66373 high CVSS 7.5

Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE,...

Summary

Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE,...

AI summary openai / gpt-4o

Redis 8.8.0未満のバージョンにおいて、認証された攻撃者がRESTOREを実行できる場合、特定の状況で同じNACKが複数の消費者によって参照されることで、XGROUP DELCONSUMERが二重解放を引き起こし、リモートコード実行が可能となる。これはCVE-2026-25243の不完全な修正が原因である。
❓ What is the problem
Redis 8.8.0未満でRESTOREコマンドを通じてリモートコード実行が可能となる脆弱性。
📍 Affected scope
Redis 8.8.0未満のバージョンで発生。
🔥 Severity
認証された攻撃者が悪用することで任意のコードをリモートで実行可能になるため、非常に深刻。
🔧 How to fix
Redisをバージョン8.8.0以上にアップデートする。
🛡️ Workaround
情報なし。
🔍 Detection
二重解放が発生しているかどうかを監視ロギングで確認する。

References

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →