Redis RCE identifiers in August 2026: a use-after-free and a fix that left work behind
Three remote code execution identifiers in one month is an unusual run for any infrastructure component, and the Redis sequence during August 2026 reads better as one story than as three separate advisories. Also, the most instructive part is not the memory corruption. It is that one of the flaws defeated an earlier fix.
Technical context
The most recent entry is tracked as QVD-2026-58458 and lives in tlsProcessPendingData(). When Redis is built with TLS support, that function walks the list of pending TLS data using an adlist iterator. Handling an event during the walk can re-enter the event loop, which lets the node the iterator cached as its successor be removed and freed. The outer traversal then continues through memory that has already been released.
Because the defect sits in the server's own memory handling, it needs no module loading, no file write and no debugger. An attacker with a normal TLS command interface can shape the heap and the timing, convert the use-after-free into read and write primitives, and end with command execution under the service account. The vendor assigned 9.8 at first and revised its own score down to 7.5 on the grounds that authentication, a low-privileged user, TLS session coordination and specific runtime conditions are all required.
Corrected releases span every maintained branch: 8.10.1, 8.8.2, 8.6.6, 8.4.6, 8.2.9, 7.4.11, 7.2.16 and 6.2.24.
Explanation and why the bypass matters
The July entry in the sequence is a bypass of the fix for CVE-2026-23479. The original patch addressed reference counting for a shared negative acknowledgement object in a stream consumer group, and it did not address that object completely. By constructing a specific order of stream operations using XGROUP, EVAL and RESTORE, an attacker can still cause a double free of the shared object and build from there. Affected ranges for the bypass include 6.2.22 and earlier, 7.4.9 and earlier and 8.6.4 and earlier, corrected in 8.8.0 and later.
That pattern is what makes the sequence a case study. Teams that treated the earlier identifier as closed and marked the asset fixed returned to an exposed state when the bypass became public, with no change on their side. A patch closes one construction, not a class of defect.
Defensive implications
Version inventory comes first, and it has to cover the environments people forget: test instances, historical deployments and services stood up by product teams outside the central process. The affected ranges cover nearly every branch in production use.
Because exploitation requires authentication, the strength of the authentication boundary is the real control. Empty or weak passwords and default ports facing a network make the prerequisite nominal. Access control lists should restrict which identities can run EVAL, XGROUP and RESTORE, since those are the commands the constructions rely on. Command audit is the detection layer: unusual sequences involving those commands, and connections from addresses that have never talked to the service before, are the signals worth alerting on. Containers deserve a separate check, because a rebuilt image can reintroduce an older binary after the host has been updated.
References
[1] Redis security advisories.
[2] NVD entry for CVE-2026-23479.
[3] CISA Known Exploited Vulnerabilities Catalog.
Top comments (0)