CVE-2026-92925: Red Hat Pen Drive Powered By Red Hat Lightspeed

High severity, CVSS 7.1. EPSS: 0.4% chance of exploitation in the next 30 days.

A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packets, fails to properly validate string-carrying extensions for null-termination. This oversight allows a remote attacker to craft a malicious packet, leading to an out-of-bounds read when the packet's payload is processed. Successful exploitation of this vulnerability could result in the disclosure of sensitive information or a remote denial of service (DoS).

Affected products

  • Red Hat Pen Drive Powered By Red Hat Lightspeed
  • Red Hat Red Hat 3scale API Management Platform 2
  • Red Hat Red Hat Enterprise Linux 10
  • Red Hat Red Hat Enterprise Linux 8
  • Red Hat Red Hat Enterprise Linux 9: before 9080020260821173335.9 (fixed in 9080020260821173335.9)
  • Red Hat Red Hat Enterprise Linux 9.4 Update Services For SAP Solutions: before 9040020260917140622.9 (fixed in 9040020260917140622.9)
  • Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support: before 9060020260917140656.9 (fixed in 9060020260917140656.9)
  • Red Hat Red Hat Hardened Images

Published 2026-09-17. Last modified 2026-10-08.