# Redis RCE CVE-2026-23479 — Use-After-Free in unblockClientOnKey() (Authenticated, CVSS 8.8)

> An authenticated use-after-free (CWE-416) in Redis's unblock-client flow (unblockClientOnKey() in src/blocked.c) enables heap corruption that chains to remote code execution as the redis-server process. Surfaced after 2+ years by Theori's autonomous Xint Code AI tool at ZeroDay.Cloud 2025 and reported by Team Xint Code; a full 3-stage exploit write-up (heap leak -> heap reclaim -> GOT overwrite) is now public.

- **Published:** 2026-06-04T00:00:00Z
- **Last reviewed:** 2026-06-04T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0682
- **ID:** TL-2026-0682
- **Severity:** HIGH (CVSS 8.8)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 12 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-23479

## Description

CVE-2026-23479 is a use-after-free vulnerability in the Redis blocked-client wake-up path. unblockClientOnKey() dispatches a queued, previously-blocked command through processCommandAndResetClient() and then continues to dereference the same client pointer. The function header explicitly warns that the client may be freed as a side effect of processing the command, yet the return value is ignored. The defect was introduced by two separate changes: PR #11012 (January 2023) added the unchecked processCommandAndResetClient() call, and PR #11568 (March 2023) added further client access after that call. It shipped in Redis 7.2.0 (late 2023) and survived multiple security review rounds across every stable branch through 8.6.2 for over two years.

Exploitation is a three-stage chain. Stage 1 (information leak): an authenticated attacker runs the Lua one-liner EVAL "return tostring(redis.call)" 0, which returns a function pointer exposing a stable Redis heap address used to populate fake-client fields. Stage 2 (UAF trigger and reclaim): the attacker grooms memory via CONFIG SET maxmemory-clients and client-output-buffer-limit, parks a bloated client blocked on a stream (XREAD BLOCK 0), then on a second connection lowers maxmemory-clients to 1 and issues XADD to wake the blocked client. The wake-up frees the blocked client during eviction, but unblockClientOnKey() keeps using the dangling pointer (zfree() does not zero memory) and queueClientForReprocessing() re-appends the freed pointer to server.unblocked_clients for same-iteration processing. A pipelined SET reclaim:<rand> <fake-client-bytes> reclaims the freed slot with an attacker-crafted client structure (controlled last_memory_type as an OOB index, last_memory_usage as a decrement, CLIENT_PENDING_COMMAND flag set, and leaked heap pointers to avoid crashes). Stage 3 (RCE): when Redis drains server.unblocked_clients it processes the reclaimed allocation via updateClientMemoryUsage(), executing server.stat_clients_type_memory[c->last_memory_type] -= c->last_memory_usage as an out-of-bounds write. With partial RELRO (default in official Redis Docker images) the .got.plt is writable, so the attacker corrupts the GOT entry for strcasecmp to point at system(). The next command parsed invokes strcasecmp() and instead runs the command string as a shell command with redis-server privileges.

The exploit requires post-authentication access with ACL categories @admin (CONFIG SET), @scripting (EVAL), @stream (XREAD/XADD), and @read/@write (SET/GET) — all granted to the default user in standard deployments. Redis reports no in-the-wild exploitation as of the 2026-05-05 advisory, but the complete technical chain is now public, elevating follow-on risk for internet-exposed or weakly-segmented instances.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1059.004 Command and Scripting Interpreter: Unix Shell
- T1106 Native API
- T1068 Exploitation for Privilege Escalation
- T1211 Exploitation for Stealth
- T1082 System Information Discovery
- T1499.004 Endpoint Denial of Service: Application or System Exploitation

## Sources

- [Redis Security Advisory — CVE-2026-23479 et al.](https://redis.io/blog/security-advisory-cve202623479-cve202625243-cve-2026-25588-cve202625589-cve-2026-23631/)
- [Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479)](https://thehackernews.com/2026/06/autonomous-ai-tool-finds-2-year-old-rce.html)
- [Redis CVE-2026-23479 Deep Dive — Full Exploit Chain](https://zeroday.cloud/blog/redis-cve-2026-23479-deep-dive)
- [NVD — CVE-2026-23479](https://nvd.nist.gov/vuln/detail/CVE-2026-23479)
- [Redis PR #11012 — introduced unchecked processCommandAndResetClient() call](https://github.com/redis/redis/pull/11012)
- [Redis PR #11568 — added client access after the unchecked call](https://github.com/redis/redis/pull/11568)
- [MITRE CWE-416: Use After Free](https://cwe.mitre.org/data/definitions/416.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0682
