Summary
Redis could retain an iterator pointer to a blocked client after processing a
sibling client triggered eviction and freed the next list node. V12 published
a proof of concept that grooms the freed heap slot and turns the dangling
client object into command execution in the redis-server process.
The upstream issue was opened on July 31, the fix was merged on August 6, and Redis listed it among the security fixes shipped in 8.8.2 on August 17. The upstream record validates the vulnerability and remediation; AI attribution remains self-reported because it is stated in V12’s own repository.
References
- V12 proof of concept: Redis remote RCE
- Redis issue #15562
- Redis fix PR #15594
- Redis 8.8.2 security release
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.