FixVibe

high

Redis RESTORE Memory-Safety Vulnerability (CVE-2026-25243)

CVE-2026-25243 is a high-severity Redis memory-safety flaw in RESTORE processing. It requires authenticated access and permission to run RESTORE, and Redis 8.6.3 includes the security fix.

CVE-2026-25243GHSA-c8h9-259x-jff4CWE-20CWE-122

What happened

Redis disclosed CVE-2026-25243, a memory-safety vulnerability in the RESTORE command caused by insufficient validation of serialized values [S1]. A specially crafted value can trigger invalid memory access and may lead to remote code execution in the Redis server process [S1].

Who is affected

The vendor advisory describes the issue as affecting Redis and requires two prerequisites: the attacker must already be authenticated to the Redis instance and must be allowed to execute RESTORE [S1]. Redis lists the issue among the security fixes in release 8.6.3 [S2].

Because the advisory page and release metadata were updated during disclosure, operators should use the vendor's current advisory and their distribution's security notice to map the fix to the exact package build they deploy [S1] [S2].

Impact

Successful exploitation may execute code in the Redis server context, potentially compromising the data and host resources available to that process. The vendor rates the issue High with a CVSS v4 base score of 7.7 and notes high potential confidentiality, integrity, and availability impact [S1].

Remediation

Upgrade to Redis 8.6.3 or a later supported release that contains the security fix [S2]. If an immediate upgrade is not possible, remove RESTORE permission from non-administrative identities with Redis ACL rules and verify that Redis is not exposed beyond trusted application and management networks [S1].

After upgrading, confirm the running server and every replica use the intended patched package, then review ACLs for identities that can invoke administrative data-loading commands [S1] [S2].

How FixVibe covers it

FixVibe's GitHub repo scans flag explicitly pinned Redis images or package versions that need the 8.6.3 security fix; confirm the running version against the deployed environment and vendor guidance [S1] [S2].