Reference page — cumulative record through Saturday, October 3, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-92925
Redis: redis: out-of-bounds read via crafted cluster bus packets
AV AC PR UI S C I A CVSS EPSS %ile KEV
A L N N U L N H 7.1 .0067 50.1 —
AFFECTED
Product Versions Fixed
Red Hat Enterprise Linux 9 unspecified 9080020260821173335.9
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions unspecified 9040020260917140622.9
Red Hat Enterprise Linux 9.6 Extended Update Support unspecified 9060020260917140656.9
Pen Drive Powered by Red Hat Lightspeed unspecified —
Red Hat 3scale API Management Platform 2 unspecified —
Red Hat 3scale API Management Platform 2 unspecified —
Red Hat 3scale API Management Platform 2 unspecified —
Red Hat Enterprise Linux 10 unspecified —
Red Hat Enterprise Linux 8 unspecified —
Red Hat Enterprise Linux 9 unspecified —
+ 2 more
TIMELINE
Sep 17 Reserved by redhat
Sep 17 Published (CNA: redhat)
Sep 21 PATCH SHIPPED — CVE-2026-92925 (Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions). Fixed in Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions 9040020260917140622.9.
Description
A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packets, fails to properly validate string-carrying extensions for null-termination. This oversight allows a remote attacker to craft a malicious packet, leading to an out-of-bounds read when the packet's payload is processed. Successful exploitation of this vulnerability could result in the disclosure of sensitive information or a remote denial of service (DoS).
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| September 17, 2026 | Reserved | Reserved by redhat |
| September 17, 2026 | Published | Published (CNA: redhat) |
| September 21, 2026 | PATCH SHIPPED | PATCH SHIPPED — CVE-2026-92925 (Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions). Fixed in Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions 9040020260917140622.9. |
Affected
Affected products and packages — 12 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Red Hat | Red Hat Enterprise Linux 9 | — | — | 9080020260821173335.9 |
| Red Hat | Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | — | — | 9040020260917140622.9 |
| Red Hat | Red Hat Enterprise Linux 9.6 Extended Update Support | — | — | 9060020260917140656.9 |
| Red Hat | Pen Drive Powered by Red Hat Lightspeed | — | — | — |
| Red Hat | Red Hat 3scale API Management Platform 2 | — | — | — |
| Red Hat | Red Hat 3scale API Management Platform 2 | — | — | — |
| Red Hat | Red Hat 3scale API Management Platform 2 | — | — | — |
| Red Hat | Red Hat Enterprise Linux 10 | — | — | — |
| Red Hat | Red Hat Enterprise Linux 8 | — | — | — |
| Red Hat | Red Hat Enterprise Linux 9 | — | — | — |
| Red Hat | Red Hat Enterprise Linux 9 | — | — | — |
| Red Hat | Red Hat Hardened Images | — | — | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-92925 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Saturday, October 3, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.