ZeroHour
Canadian Centre for Cyber Securitypublished ()ingested Canadian Centre for Cyber Security

Redis security advisory (AV26-859)

mediumAdvisoryimportance 32
AI summary · glm-5.3-flash

Canada's Cyber Centre flagged a use-after-free in Redis 8.0's TLS handling, fixed in versions 8.2.9, 8.4.6, 8.6.6, 8.8.2, and 8.10.1.

Canada's Cyber Centre issued advisory AV26-859 for a use-after-free bug in Redis's tlsProcessPendingData() pending-list iteration, affecting the Redis 8.0 series. Fixed releases include 8.2.9, 8.4.6, 8.6.6, 8.8.2, and 8.10.1. Users and administrators are encouraged to review vendor guidance and update. No CVE identifier or exploitation details were provided in the advisory text.

  • Use-after-free in tlsProcessPendingData() pending-list iteration
  • Affects Redis 8.0 series; fixed in 8.2.9, 8.4.6, 8.6.6, 8.8.2, and 8.10.1
  • Advisory relayed by Canada's Cyber Centre
VendorsRedis
ProductsRedis 8.0
CountriesCanada
Full article

Serial Number: AV26-859 Date: August 28, 2026 As of August 27, 2026, Redis is affected by a vulnerability in the following product: Redis 8.0 All except 8.10.1 All except 8.2.9 All except 8.4.6 All except 8.6.6 All except 8.8.2 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Fix use-after-free in tlsProcessPendingData() pending-list iteration GitHub Releases

This source does not provide full text. Read it at cyber.gc.ca.