# Redis Streams Shared-NACK Double-Free (CVE-2026-25243) & RedisBloom RESTORE/TDigest Heap Overflow (CVE-2026-25589) — Authenticated RCE, Public PoC, Patch Bypass

> Security researchers 'Bera Buddies', using an AI agent (Kimi K3), publicly disclosed on 2026-07-23 that Redis's May 2026 fix for a Streams consumer-group shared-NACK double-free (CVE-2026-25243) was incomplete on 'patched' Redis 6.2.22, 7.4.9 and 8.6.4, and separately found a new, then-unpatched heap overflow in the bundled RedisBloom TDigest RDB loader affecting fresh Redis 8.8.0 installs (part of the CVE-2026-25589 RESTORE/RedisBloom family). Both give an authenticated client with access to commonly enabled commands (RESTORE, EVAL, XGROUP) a reliable primitive for remote code execution; a working public PoC is on GitHub, Redis shipped seven emergency releases the same day, and no in-the-wild exploitation or CISA KEV listing has been confirmed as of 2026-07-25.

- **Published:** 2026-07-23T00:00:00Z
- **Last reviewed:** 2026-07-23T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1690
- **ID:** TL-2026-1690
- **Severity:** HIGH (CVSS 8.8)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 20 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-25589, CVE-2026-25243

## Description

On 2026-05-05 Redis published a coordinated security advisory covering five vulnerabilities discovered largely through the Wiz ZeroDay.Cloud research event: CVE-2026-23479 (unblock-client use-after-free), CVE-2026-25243 (RESTORE command double-free/invalid memory access in core Redis, reported by Emil Lerner and Joseph Surin), CVE-2026-25588 (RESTORE + RedisTimeSeries invalid memory access), CVE-2026-25589 (RESTORE + RedisBloom invalid memory access, reported by Daniel Firer and Joseph Surin), and CVE-2026-23631 (Lua scripting use-after-free on replicas). Redis shipped fixed releases the same day (OSS/CE 6.2.22, 7.2.14, 7.4.9, 8.2.6, 8.4.3, 8.6.3; RedisBloom 2.8.20; RedisTimeSeries 1.12.14) and stated no evidence of exploitation.

On 2026-07-23, the AI-agent security research group 'Bera Buddies' (researcher Chaofan Shou publicizing on X) disclosed that the May fix for the Streams shared-NACK ownership bug (CVE-2026-25243) never actually shipped in the 6.2.22, 7.4.9 and 8.6.4 releases users had been told to install — a patch-verification gap, not a new root cause — making a reliable authenticated RCE chain reproducible on 'patched' installs (10/10 on 6.2.22, 5/5 on 7.4.9, 25/25 on 8.6.4 in the public PoC). Separately, they found a genuinely new, previously unpatched heap overflow in the bundled RedisBloom TDigest RDB loader on fresh Redis 8.8.0 instances: the loader allocates a centroid array sized from the serialized compression value but then trusts a separate, attacker-controlled capacity field when deciding how many nodes to load, producing a small real allocation paired with inflated metadata and an out-of-bounds write. This TDigest bug is part of the broader RESTORE+RedisBloom vulnerability class tracked as CVE-2026-25589.

Both chains require RESTORE to deliver the malformed serialized payload; the Streams chain additionally needs EVAL and XGROUP. The published exploit chain proceeds: (1) a malformed RESTORE payload (corrupt zipmap or a stream with duplicate NACK entries) triggers the double-free; (2) the attacker sprays uniquely-marked Redis strings to find overlapping heap allocations; (3) SETRANGE overwrites object headers on the overlap to forge a ~1MB fake SDS string as a read/write memory viewport; (4) predictable INCRBYFLOAT float allocations are located and their pointers redirected through the viewport, giving arbitrary read/write via GETRANGE/SETRANGE; (5) the heap is scanned from known addresses for the global redisServer struct, identified by recognizable fields (pid, thread_id, executable path, config values); (6) server.executable and server.exec_argv are overwritten in memory to point at /bin/sh and shell arguments, the DEBUG command is enabled, and DEBUG CRASH-AND-RECOVER is issued to force execve() and hand the attacker a shell. The PoC notes the technique is layout-sensitive on 8.8.0 (jemalloc memory layout, retries needed on grooming misses) and that it leaves inert exploit keys and corrupted structures behind — operators are advised to avoid FLUSHALL/SAVE, which could mask forensic residue.

Redis responded the same day (2026-07-23) with seven emergency releases: 6.2.23, 7.2.15 and 7.4.10 fix the Streams shared-NACK use-after-free that the May releases had missed; 8.2.8, 8.4.5 and 8.6.5 fix both the Streams issue and the RedisBloom/TDigest out-of-bounds write; 8.8.1 fixes the RedisBloom/TDigest loader specifically (the Streams guard was already present in 8.8.0). As of 2026-07-25, CVE-2026-25243 carries CVSS v3.1 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) and CVE-2026-25589 carries CVSS v4.0 7.7; neither CVE appears in the CISA Known Exploited Vulnerabilities catalog and Redis states it has no evidence of exploitation in its own environment or customer environments. Exploitation in all cases is strictly post-authentication and depends on the attacker's Redis identity being permitted to run RESTORE (and, for the Streams chain, EVAL/XGROUP) — a permission surface Redis's own advisory calls out as commonly over-granted in internal deployments.

## MITRE ATT&CK

- T1595 Active Scanning
- T1592.004 Client Configurations
- T1588.006 Vulnerabilities
- T1587.001 Malware
- T1078 Valid Accounts
- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1059.004 Unix Shell
- T1210 Exploitation of Remote Services
- T1068 Exploitation for Privilege Escalation
- T1620 Reflective Code Loading
- T1070 Indicator Removal
- T1554 Compromise Host Software Binary
- T1082 System Information Discovery
- T1518 Software Discovery
- T1489 Service Stop

## Sources

- [Redis Server 0-Day Exploit](https://cybersecuritynews.com/redis-server-0-day-exploit/)
- [redis-poc (public proof-of-concept)](https://github.com/berabuddies/redis-poc)
- [Security advisory: CVE-2026-23479, CVE-2026-25243, CVE-2026-25588, CVE-2026-25589, CVE-2026-23631](https://redis.io/blog/security-advisory-cve202623479-cve202625243-cve-2026-25588-cve202625589-cve-2026-23631/)
- [GHSA-7862-34pw-44wv — RedisBloom RESTORE command invalid memory access](https://github.com/RedisBloom/RedisBloom/security/advisories/GHSA-7862-34pw-44wv)
- [NVD — CVE-2026-25589](https://nvd.nist.gov/vuln/detail/CVE-2026-25589)
- [NVD — CVE-2026-25243](https://nvd.nist.gov/vuln/detail/CVE-2026-25243)
- [CVE-2026-25243: Two Redis RESTORE Bugs Leading to RCE (deep dive)](https://www.zeroday.cloud/blog/redis-cve-2026-25243-deep-dive)
- [Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say](https://thehackernews.com/2026/07/kimi-k3-agents-found-redis-zero-days.html)
- [CVE-2026-25243 — SentinelOne Vulnerability Database](https://www.sentinelone.com/vulnerability-database/cve-2026-25243/)
- [Critical Redis Patches Fix RCE and Memory Corruption Flaws](https://securityonline.info/redis-rce-vulnerabilities-memory-corruption-restore-command-patch/)
- [Redis release 8.6.3](https://github.com/redis/redis/releases/tag/8.6.3)
- [GHSA-c8h9-259x-jff4 — Redis RESTORE command invalid memory access](https://github.com/redis/redis/security/advisories/GHSA-c8h9-259x-jff4)
- [Wiz ZeroDay.Cloud](https://www.zeroday.cloud/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1690
