Redis Zero-Days Enable RCE via Memory Corruption in RESTORE Command
Two critical zero-day vulnerabilities were discovered in multiple versions of Redis (6.2, 7.4, 8.6, and 8.8), stemming from memory corruption flaws in the RESTORE command that can lead to Remote Code Execution. What makes this particularly notable is that the vulnerabilities were identified by AI-powered agents (Kimi K3), signaling an emerging shift in how both defenders and adversaries discover flaws. Organizations running unpatched Redis instances — especially those exposed to untrusted networks — face serious risk of full system compromise. Redis has responded by releasing seven security updates, underscoring the urgency of prompt patching and command-level access restrictions. This incident highlights that even foundational infrastructure components like in-memory data stores must be continuously monitored and hardened.
Tactical Insight
Immediate actions
- Upgrade all Redis instances to the latest patched version as released in Redis's seven security updates.
- Restrict or disable the RESTORE command for untrusted or external clients using Redis ACLs.
- Audit all internet-facing or network-accessible Redis deployments and apply network-level controls immediately.
Long-term improvements
- Maintain a continuously updated software inventory (CMDB) that tracks all Redis versions deployed across environments.
- Integrate automated vulnerability scanning into CI/CD pipelines and infrastructure monitoring to detect newly disclosed CVEs within hours.
- Establish a formal emergency patching SLA (e.g., <24 hours for critical RCE vulnerabilities) with documented escalation procedures.
Detection measures
- Enable Redis command logging and ship logs to a centralized SIEM to detect anomalous use of the RESTORE command.
- Deploy network intrusion detection rules to alert on unexpected Redis traffic patterns or connections from untrusted sources.
- Subscribe to Redis security advisories and threat intelligence feeds to receive zero-day disclosures proactively.