All findings

v12-redis-sibling-eviction-uaf high

V12 turns a Redis sibling-eviction use-after-free into remote code execution

V12 reported and exploited a Redis blocked-client iterator flaw; upstream merged the fix and shipped it in Redis 8.8.2.

Bug class
Heap use-after-free leading to remote code execution
Affected codebase
Redis
Credited system
V12
Disclosed
August 17, 2026
Attribution
Self-reported attribution
Severity
high
Source status: Redis's public issue, merged pull request, and 8.8.2 security release independently corroborate the bug and fix. The claim that V12 discovered it comes from the V12 team's public proof-of-concept repository.

Summary

Redis could retain an iterator pointer to a blocked client after processing a sibling client triggered eviction and freed the next list node. V12 published a proof of concept that grooms the freed heap slot and turns the dangling client object into command execution in the redis-server process.

The upstream issue was opened on July 31, the fix was merged on August 6, and Redis listed it among the security fixes shipped in 8.8.2 on August 17. The upstream record validates the vulnerability and remediation; AI attribution remains self-reported because it is stated in V12’s own repository.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.