hacker-news · Crawled Jul 24, 2026
Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say
4 IoCs 2 CVEs
Read original article ↗
AI Summary
Redis disclosed and patched multiple memory corruption vulnerabilities in its database software that could lead to authenticated remote code execution (RCE). Two distinct exploit chains were identified: one leveraging a shared-NACK use-after-free in Redis Streams, and another exploiting an out-of-bounds write in the RedisBloom TDigest RDB loader. Both vulnerabilities require the RESTORE command and were exploited in proof-of-concept (PoC) scripts to achieve arbitrary memory access and system command execution. The flaws affect multiple Redis versions, including 6.2.22, 7.4.9, 8.6.4, and 8.8.0, with fixes released on July 23, 2026.
AI-extracted · verify before operational use