Security8.2.9
Redis 8.2.9 Security Fixes
Redis 8.2.9 addresses multiple critical security vulnerabilities including buffer overflow in CMSketch RDB loading, out-of-bounds access issues, use-after-free flaws in TLS and blocking clients, ACL key permission bypass in several commands, and Vector Sets memory safety issues. These fixes prevent potential heap corruption, remote code execution, and unauthorized data access.
Security fixes
- (CVE-2026-62356) Miscalculated buffer size in
CMSketchRDB loading may lead to heap OOB write - Out-of-bounds access in TopK heap cleanup path (MOD-15410)
- Use-after-free in the TLS pending-data list when a command closes another pending connection
- #15478 ACL key permission bypass in
SORT,GEORADIUS/GEORADIUSBYMEMBERandXREAD/XREADGROUP: the keys validated by ACL could differ from the keys the command actually accesses - #14847 Out-of-bounds
argvaccess during key extraction when checking ACL permissions of a KEYNUM keyspec command (e.g.EVAL) with wrong arity - A malicious RDB payload with an out-of-range
SLOT_INFOslot id causes memory corruption during RDB loading, which may lead to Remote Code Execution - Vector Sets: missing node level validation when loading a vector set from RDB may lead to out-of-bounds access
- Vector Sets: use-after-free when
VREMmutates the HNSW graph while backgroundVSIMthreads are still running - Vector Sets: a negative
hnsw_search()return was treated as a huge unsigned count, reading past the end of the result arrays - #15594 Use-after-free in the blocked-client list when reprocessing a command evicts another client blocked on the same key
securityrdbaclvector-setsmemory-safety
Source: original entry ↗