Threat reportVulnerabilityTL-2026-1690
Redis Streams Shared-NACK Double-Free (CVE-2026-25243) & RedisBloom RESTORE/TDigest Heap Overflow (CVE-2026-25589) — Authenticated RCE, Public PoC, Patch Bypass
Redis Streams Shared-NACK Double-Free (CVE-2026-25243) & (TL-2026-1690), also tracked as Redis Streams Shared-NACK Double-Free, is a high-severity software vulnerability scored CVSS 8.8, first published 2026-07-23. It has no confirmed attribution, affects Redis Redis (redis-server: OSS, Community Edition, Software, Cloud), references 2 CVEs (CVE-2026-25589, CVE-2026-25243), maps to 16 MITRE ATT&CK techniques (T1059, T1059.004, T1068), and is covered by 9 detection rules and 20 indicators of compromise.
- CVSS
- 8.8/10High
- CVEs
- 2Referenced vulnerabilities
- Techniques
- 16MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 20Indicators of compromise
Key facts for TL-2026-1690
- Threat ID
- TL-2026-1690
- Also known as
- Redis Streams Shared-NACK Double-Free, RedisBloom TDigest Heap Overflow, Redis 0-Day Exploit (Kimi K3 / Bera Buddies), Redis RESTORE Patch-Bypass RCE
- Severity
- HIGH
- CVSS
- 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, cloud-computing, financial-services, ecommerce, saas, gaming
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in Redis Streams Shared-NACK Double-Free (CVE-2026-25243) &
Malware and tooling: Kimi K3, libcrc64.so
How Redis Streams Shared-NACK Double-Free (CVE-2026-25243) & works
Security researchers 'Bera Buddies', using an AI agent (Kimi K3), publicly disclosed on 2026-07-23 that Redis's May 2026 fix for a Streams consumer-group shared-NACK double-free (CVE-2026-25243) was incomplete on 'patched' Redis 6.2.22, 7.4.9 and 8.6.4, and separately found a new, then-unpatched heap overflow in the bundled RedisBloom TDigest RDB loader affecting fresh Redis 8.8.0 installs (part of the CVE-2026-25589 RESTORE/RedisBloom family). Both give an authenticated client with access to commonly enabled commands (RESTORE, EVAL, XGROUP) a reliable primitive for remote code execution; a working public PoC is on GitHub, Redis shipped seven emergency releases the same day, and no in-the-wild exploitation or CISA KEV listing has been confirmed as of 2026-07-25.
On 2026-05-05 Redis published a coordinated security advisory covering five vulnerabilities discovered largely through the Wiz ZeroDay.Cloud research event: CVE-2026-23479 (unblock-client use-after-free), CVE-2026-25243 (RESTORE command double-free/invalid memory access in core Redis, reported by Emil Lerner and Joseph Surin), CVE-2026-25588 (RESTORE + RedisTimeSeries invalid memory access), CVE-2026-25589 (RESTORE + RedisBloom invalid memory access, reported by Daniel Firer and Joseph Surin), and CVE-2026-23631 (Lua scripting use-after-free on replicas). Redis shipped fixed releases the same day (OSS/CE 6.2.22, 7.2.14, 7.4.9, 8.2.6, 8.4.3, 8.6.3; RedisBloom 2.8.20; RedisTimeSeries 1.12.14) and stated no evidence of exploitation.
On 2026-07-23, the AI-agent security research group 'Bera Buddies' (researcher Chaofan Shou publicizing on X) disclosed that the May fix for the Streams shared-NACK ownership bug (CVE-2026-25243) never actually shipped in the 6.2.22, 7.4.9 and 8.6.4 releases users had been told to install — a patch-verification gap, not a new root cause — making a reliable authenticated RCE chain reproducible on 'patched' installs (10/10 on 6.2.22, 5/5 on 7.4.9, 25/25 on 8.6.4 in the public PoC). Separately, they found a genuinely new, previously unpatched heap overflow in the bundled RedisBloom TDigest RDB loader on fresh Redis 8.8.0 instances: the loader allocates a centroid array sized from the serialized compression value but then trusts a separate, attacker-controlled capacity field when deciding how many nodes to load, producing a small real allocation paired with inflated metadata and an out-of-bounds write. This TDigest bug is part of the broader RESTORE+RedisBloom vulnerability class tracked as CVE-2026-25589.
Both chains require RESTORE to deliver the malformed serialized payload; the Streams chain additionally needs EVAL and XGROUP. The published exploit chain proceeds: (1) a malformed RESTORE payload (corrupt zipmap or a stream with duplicate NACK entries) triggers the double-free; (2) the attacker sprays uniquely-marked Redis strings to find overlapping heap allocations; (3) SETRANGE overwrites object headers on the overlap to forge a ~1MB fake SDS string as a read/write memory viewport; (4) predictable INCRBYFLOAT float allocations are located and their pointers redirected through the viewport, giving arbitrary read/write via GETRANGE/SETRANGE; (5) the heap is scanned from known addresses for the global redisServer struct, identified by recognizable fields (pid, thread_id, executable path, config values); (6) server.executable and server.exec_argv are overwritten in memory to point at /bin/sh and shell arguments, the DEBUG command is enabled, and DEBUG CRASH-AND-RECOVER is issued to force execve() and hand the attacker a shell. The PoC notes the technique is layout-sensitive on 8.8.0 (jemalloc memory layout, retries needed on grooming misses) and that it leaves inert exploit keys and corrupted structures behind — operators are advised to avoid FLUSHALL/SAVE, which could mask forensic residue.
Redis responded the same day (2026-07-23) with seven emergency releases: 6.2.23, 7.2.15 and 7.4.10 fix the Streams shared-NACK use-after-free that the May releases had missed; 8.2.8, 8.4.5 and 8.6.5 fix both the Streams issue and the RedisBloom/TDigest out-of-bounds write; 8.8.1 fixes the RedisBloom/TDigest loader specifically (the Streams guard was already present in 8.8.0). As of 2026-07-25, CVE-2026-25243 carries CVSS v3.1 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) and CVE-2026-25589 carries CVSS v4.0 7.7; neither CVE appears in the CISA Known Exploited Vulnerabilities catalog and Redis states it has no evidence of exploitation in its own environment or customer environments. Exploitation in all cases is strictly post-authentication and depends on the attacker's Redis identity being permitted to run RESTORE (and, for the Streams chain, EVAL/XGROUP) — a permission surface Redis's own advisory calls out as commonly over-granted in internal deployments.
MITRE ATT&CK techniques used in TL-2026-1690
Execution
T1059 Command and Scripting Interpreter; T1059.004 Unix Shell
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Defense Evasion
T1070 Indicator Removal; T1620 Reflective Code Loading
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application
Discovery
T1082 System Information Discovery; T1518 Software Discovery
lateral-movement
T1210 Exploitation of Remote Services
Impact
Persistence
T1554 Compromise Host Software Binary
Resource Development
T1587.001 Malware; T1588.006 Vulnerabilities
Reconnaissance
Affected products and versions in Redis Streams Shared-NACK Double-Free (CVE-2026-25243) &
- Redis — Redis (redis-server: OSS, Community Edition, Software, Cloud)
Vulnerable versions: 6.2.22 (patch-bypass; NACK guard missing); 7.2.14 (pre-7.2.15); 7.4.9 (patch-bypass; NACK guard missing); 8.2.6 (pre-8.2.8); 8.4.3 (pre-8.4.5); 8.6.3 and 8.6.4 (patch-bypass; NACK guard missing, pre-8.6.5); 8.8.0 (RedisBloom TDigest loader unpatched)
Fixed in: 6.2.23; 7.2.15; 7.4.10; 8.2.8; 8.4.5; 8.6.5; 8.8.1 - Redis — RedisBloom module
Vulnerable versions: < 2.8.20 (RESTORE out-of-bounds read/write, CVE-2026-25589); bundled with Redis 8.8.0 (TDigest RDB loader out-of-bounds write, fixed only in the 2026-07-23 release train)
Fixed in: 2.8.20; 2.6.28; 2.4.23; TDigest loader fix shipped in Redis 8.8.1 / 8.6.5 / 8.4.5 / 8.2.8 - Redis — RedisTimeSeries module
Vulnerable versions: < 1.12.14 / 1.10.24 / 1.8.23 (RESTORE out-of-bounds read/write, CVE-2026-25588)
Fixed in: 1.12.14; 1.10.24; 1.8.23
Remediation for Redis Streams Shared-NACK Double-Free (CVE-2026-25243) &
Patches
- Redis OSS/CE 6.2.23, 7.2.15, 7.4.10, 8.2.8, 8.4.5, 8.6.5, 8.8.1 (2026-07-23, Streams + RedisBloom/TDigest fixes)
- RedisBloom 2.8.20 / 2.6.28 / 2.4.23 (2026-05-05, RESTORE OOB read/write fix)
- RedisTimeSeries 1.12.14 / 1.10.24 / 1.8.23 (2026-05-05, RESTORE OOB read/write fix)
- Redis Software 8.0.10-64, 7.22.2-79, 7.8.6-253, 7.4.6-279, 7.2.4-153 (2026-05-05 batch)
Immediate actions
- Upgrade self-managed Redis to a fixed 2026-07-23 release: 6.2.23, 7.2.15, 7.4.10, 8.2.8, 8.4.5, 8.6.5, or 8.8.1 — do not treat the May releases (6.2.22/7.2.14/7.4.9/8.6.3) as sufficient; they did not include the Streams shared-NACK ownership guard
- Upgrade RedisBloom to >= 2.8.20 (or the version bundled in the 2026-07-23 Redis releases) and RedisTimeSeries to >= 1.12.14/1.10.24/1.8.23
- Restrict or remove RESTORE, EVAL, and XGROUP from non-essential ACL profiles; use `ACL SETUSER <user> -restore -eval` style rules
- Disable the DEBUG command in production via ACL if not required operationally
- Bind Redis to private/internal interfaces only; never expose port 6379 to the public internet
- Rotate credentials for any account with RESTORE/EVAL/XGROUP permissions
Workarounds
- Restrict RESTORE command access via Redis ACL rules until upgrade is complete
- Use `rename-command` to obscure/disable EVAL, RESTORE and other high-risk commands where ACLs are unavailable
- Enforce protected-mode and strong unique authentication credentials on every instance
Longer-term hardening
- Disable unused bundled modules (RedisBloom, RedisTimeSeries) if not in active use
- Adopt least-privilege ACLs for all Redis client identities rather than broad command access
- Monitor for anomalous RESTORE/EVAL/XGROUP invocations and unexpected redis-server crashes with Lua-engine stack traces
- Treat 'we set a password' as insufficient; pair authentication with command-surface restriction and network segmentation
- Track Redis security advisories continuously — this disclosure shows a vendor-issued fix can itself be incomplete
CVEs associated with Redis Streams Shared-NACK Double-Free (CVE-2026-25243) &
Weaknesses (CWE) in Redis Streams Shared-NACK Double-Free (CVE-2026-25243) &
Timeline of Redis Streams Shared-NACK Double-Free (CVE-2026-25243) &
- Redis ships OSS/CE 6.2.22, 7.2.14, 7.4.9, 8.2.6, 8.4.3, 8.6.3, RedisBloom 2.8.20 and RedisTimeSeries 1.12.14 as fixed releases; the Streams shared-NACK ownership guard is later found missing from 6.2.22, 7.4.9 and 8.6.4/8.6.3-line builds.
- Redis publishes a coordinated security advisory for five CVEs (CVE-2026-23479, CVE-2026-25243, CVE-2026-25588, CVE-2026-25589, CVE-2026-23631), most discovered at the Wiz ZeroDay.Cloud event, and states no evidence of exploitation.
- Redis ships seven emergency releases the same day: 6.2.23, 7.2.15, 7.4.10 (Streams shared-NACK fix); 8.2.8, 8.4.5, 8.6.5 (Streams + RedisBloom/TDigest fix); 8.8.1 (RedisBloom/TDigest loader fix).
- The Hacker News publishes 'Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say,' noting Redis attributes CVE-2026-25589 specifically to RedisBloom memory corruption during RESTORE, not the Streams shared-NACK flaw.
- Cyber Security News publishes 'Redis Server 0-Day Exploit,' the article that seeded this threat record.
- Bera Buddies publicly discloses and publishes a working PoC (github.com/berabuddies/redis-poc) demonstrating reliable authenticated RCE against 'patched' Redis 6.2.22/7.4.9/8.6.4 (patch bypass) and unpatched Redis 8.8.0 (RedisBloom TDigest).
- Bera Buddies uses Kimi K3 AI agents to rediscover that the May Streams fix did not fully land and to find a new heap overflow in RedisBloom's TDigest RDB loader on fresh Redis 8.8.0, self-reporting rapid (minutes-scale) discovery and exploit generation.
- CISA's Known Exploited Vulnerabilities catalog is checked and contains no entries for any of the five Redis CVEs or for Redis as a vendor, consistent with no confirmed in-the-wild exploitation.
- NVD records for CVE-2026-25589 and CVE-2026-25243 show a last-modified date reflecting updated CVSS scoring and reference data.
Sources cited for Redis Streams Shared-NACK Double-Free (CVE-2026-25243) &
- Redis Server 0-Day Exploit
- redis-poc (public proof-of-concept)
- Security advisory: CVE-2026-23479, CVE-2026-25243, CVE-2026-25588, CVE-2026-25589, CVE-2026-23631
- GHSA-7862-34pw-44wv — RedisBloom RESTORE command invalid memory access
- NVD — CVE-2026-25589
- NVD — CVE-2026-25243
- CVE-2026-25243: Two Redis RESTORE Bugs Leading to RCE (deep dive)
- Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say
- CVE-2026-25243 — SentinelOne Vulnerability Database
- Critical Redis Patches Fix RCE and Memory Corruption Flaws
- Redis release 8.6.3
- GHSA-c8h9-259x-jff4 — Redis RESTORE command invalid memory access
- Wiz ZeroDay.Cloud
Detection coverage for TL-2026-1690
As of 2026-07-23, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1690 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.