vulns.co
/
GKData.io MCP

MEMemory safety and parser contracts · 3 min read

Redis deserialization cleanup violated object-ownership invariants

Wiz confirms USD 30,000 for Emil Lerner’s Redis competition entry. Two related disclosed defects remain one awarded entry.

Read the primary source MEMemory safety and parser contractsReviewed 2026-10-02

Root cause

The researcher traced object ownership through deserialization and failure cleanup. Validation and conversion interpreted legacy data differently, while another cleanup path released an object still owned elsewhere. Both defects violated the invariant that each allocation is released exactly once; accepting a data-import request did not make its contents trustworthy.

Demonstrated impact

The researcher demonstrated code execution in the competition. The vendor confirms possible execution under Redis-process authority for an authenticated user with import permission. Host or tenant reach depends on deployment privileges and isolation; it is not established for every Redis installation.

Lessons for review

  • Make ownership transfer and cleanup responsibility explicit on success and failure paths.
  • Require validators and converters to interpret the same serialized representation consistently.
  • Follow vendor patch guidance; restrict unnecessary import permissions using access controls while remediation is assessed.

Award and evidence

USD 30,000Competition Award · Organizer Confirmed

One individually identified competition entry. The organizer uses $; its current rules establish US-dollar notation but concern 2026, not an archived 2025 rules snapshot. Exact award decision and cash settlement are unknown.

Matched the individual award, exact CVE tracker row, named researcher explanation and vendor advisory. Checked release metadata for the fix date and kept two defects inside the single awarded entry.

  • The vendor advisory also credits Joseph Surin; the reviewed award names Emil Lerner only, so no reward allocation to the additional credited researcher is inferred.
  • The advisory’s patched-version field still says TBD, while the official 8.6.3 release explicitly lists the CVE as fixed; the CNA affected range also excludes 8.6.3.
  • The researcher explains double-free mechanisms, while the CNA supplies CWE-122; neither classification is silently substituted for the other.
  • Original vendor-report, award decision and settlement dates remain unknown; June 2 publication year is inferred.
  • Current rules provide explicit USD context but are not the archived 2025 rules.

Recorded timeline

Published
2026-06-02inferred · The article displays June 2; 2026 is inferred from its completed May 5, 2026 remediation timeline.
Public Disclosure
2025-12-10explicit · Public competition demonstration; separate from later vendor advisory and technical publication.
Fixed
2026-05-05explicit · Official Redis 8.6.3 release names the CVE. Researcher also identifies fixed versions in four other maintained series.
Award Announced
2025-12-16explicit · Organizer recap confirms the per-entry award; decision and payment dates remain unknown.

Sources and provenance

  1. ZeroDay.cloud 2025 individual competition results Nir Ohfeld / Wiz Research · reviewed 2026-10-02
  2. ZeroDay.cloud vulnerability tracker Wiz / ZeroDay.cloud · reviewed 2026-10-02
  3. ZeroDay.cloud current rules: US-dollar denomination Wiz · reviewed 2026-10-02
  4. CVE-2026-25243: Two Redis RESTORE Bugs Leading to RCE Emil Lerner / ZeroDay.cloud · reviewed 2026-10-02
  5. Redis serialized-value validation advisory GHSA-c8h9-259x-jff4 Redis · reviewed 2026-10-02
  6. CVE-2026-25243 CNA record Redis / GitHub CNA · reviewed 2026-10-02
  7. Redis 8.6.3 security release Redis · reviewed 2026-10-02

Record reviewed 2026-10-02. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software