Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8ghh-qpmp-7826

Опубликовано: 05 мая 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.1

Описание

Lua Use-After-Free may lead to remote code execution

Impact

An authenticated user may exploit the synchronization mechanism of the master-replica and trigger a use-after-free vulnerability, potentially leading to remote code execution.

The bug affects only replicas that are configured, or may be configured with replica-read-only disabled , and exists in all versions of Redis with Lua scripting

Workarounds

An additional workaround to mitigate the problem without patching the redis-server executable is to prevent users from executing Lua scripts or avoid using replicas where replica-read-only is disabled

Credit

The issue was reported by independent researcher Yoni Sherez identified DarkReplica during the Wiz Zeroday Cloud event.

Пакеты

Наименование

redis

redis
Затронутые версииВерсия исправления

>=6.2.0, <6.2.22

6.2.22

Наименование

redis

redis
Затронутые версииВерсия исправления

>=7.2.0, <7.2.14

7.2.14

Наименование

redis

redis
Затронутые версииВерсия исправления

>=7.4.0, <7.4.9

7.4.9

Наименование

redis

redis
Затронутые версииВерсия исправления

>=8.2.0, <8.2.6

8.2.6

Наименование

redis

redis
Затронутые версииВерсия исправления

>=8.4.0, <8.4.3

8.4.3

Наименование

redis

redis
Затронутые версииВерсия исправления

>=8.6.0, <8.6.3

8.6.3

EPSS

Процентиль: 76%
0.01782
Низкий

6.1 Medium

CVSS4

Дефекты

CWE-416

Связанные уязвимости

CVSS3: 8.1
ubuntu
3 месяца назад

Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled or can be disabled, which may lead to remote code execution. A workaround is to prevent users from executing Lua scripts or avoid using replicas where replica-read-only is disabled. This is patched in version 8.6.3.

CVSS3: 8.8
redhat
3 месяца назад

Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled or can be disabled, which may lead to remote code execution. A workaround is to prevent users from executing Lua scripts or avoid using replicas where replica-read-only is disabled. This is patched in version 8.6.3.

CVSS3: 8.1
nvd
3 месяца назад

Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled or can be disabled, which may lead to remote code execution. A workaround is to prevent users from executing Lua scripts or avoid using replicas where replica-read-only is disabled. This is patched in version 8.6.3.

msrc
около 2 месяцев назад

redis-server Lua use-after-free may allow remote code execution

CVSS3: 8.1
debian
3 месяца назад

Redis is an in-memory data structure store. In all versions of redis-s ...

EPSS

Процентиль: 76%
0.01782
Низкий

6.1 Medium

CVSS4

Дефекты

CWE-416