Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-49844

Опубликовано: 03 окт. 2025
Источник: ubuntu
Приоритет: high
EPSS Высокий
CVSS3: 9.9

Описание

Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to manipulate the garbage collector, trigger a use-after-free and potentially lead to remote code execution. The problem exists in all versions of Redis with Lua scripting. This issue is fixed in version 8.2.2. To workaround this issue without patching the redis-server executable is to prevent users from executing Lua scripts. This can be done using ACL to restrict EVAL and EVALSHA commands.

РелизСтатусПримечание
devel

needed

esm-apps/bionic

needed

esm-apps/focal

released

5.1.5-8.1ubuntu0.20.04.1~esm1
esm-apps/jammy

released

5.1.5-8.1ubuntu0.22.04.1~esm1
esm-apps/noble

needed

esm-apps/resolute

needed

esm-infra-legacy/trusty

needed

esm-infra-legacy/xenial

released

5.1.5-8ubuntu1+esm1
esm-infra/xenial

ignored

end of ESM support, was needed
jammy

needed

Показывать по

РелизСтатусПримечание
devel

not-affected

code not present
esm-apps/jammy

not-affected

code not present
esm-apps/noble

not-affected

code not present
esm-apps/resolute

not-affected

code not present
esm-infra-legacy/trusty

not-affected

code not present
esm-infra-legacy/xenial

not-affected

code not present
esm-infra/bionic

not-affected

code not present
esm-infra/focal

not-affected

code not present
esm-infra/xenial

not-affected

code not present
jammy

not-affected

code not present

Показывать по

РелизСтатусПримечание
devel

not-affected

code not present
esm-apps/noble

not-affected

code not present
esm-apps/resolute

not-affected

code not present
esm-infra-legacy/xenial

not-affected

code not present
esm-infra/bionic

not-affected

code not present
esm-infra/focal

not-affected

code not present
esm-infra/xenial

not-affected

code not present
jammy

not-affected

code not present
noble

not-affected

code not present
questing

not-affected

code not present

Показывать по

РелизСтатусПримечание
devel

not-affected

code not present
esm-apps/jammy

not-affected

code not present
jammy

not-affected

code not present
noble

not-affected

code not present
questing

not-affected

code not present
resolute

not-affected

code not present
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps-legacy/xenial

needed

esm-apps/bionic

needed

esm-apps/focal

needed

esm-apps/xenial

ignored

end of ESM support, was needed
jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

not-affected

7.3.5+ds-1ubuntu0.1
esm-apps/resolute

not-affected

7.3.5+ds-1ubuntu0.1
jammy

DNE

noble

DNE

plucky

released

7.3.2+ds-1ubuntu0.1
questing

released

7.3.5+ds-1ubuntu0.1
resolute

not-affected

7.3.5+ds-1ubuntu0.1
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

not-affected

5:8.0.2-3ubuntu0.25.10.1
esm-apps-legacy/xenial

released

2:3.0.6-1ubuntu0.4+esm4
esm-apps/bionic

released

5:4.0.9-1ubuntu0.2+esm6
esm-apps/focal

not-affected

5:5.0.7-2ubuntu0.1+esm3
esm-apps/jammy

not-affected

5:6.0.16-1ubuntu1
esm-apps/noble

released

5:7.0.15-1ubuntu0.24.04.2
esm-apps/resolute

not-affected

5:8.0.2-3ubuntu0.25.10.1
esm-apps/xenial

released

2:3.0.6-1ubuntu0.4+esm4
esm-infra-legacy/trusty

released

2:2.8.4-2ubuntu0.2+esm5
jammy

not-affected

5:6.0.16-1ubuntu1

Показывать по

РелизСтатусПримечание
devel

not-affected

9.0.3-0ubuntu1
esm-apps/noble

released

7.2.11+dfsg1-0ubuntu0.2
jammy

DNE

noble

released

7.2.11+dfsg1-0ubuntu0.2
plucky

released

8.0.6+dfsg1-0ubuntu0.2
questing

released

8.1.4+dfsg1-0ubuntu0.2
resolute

not-affected

9.0.3-0ubuntu1
upstream

needs-triage

Показывать по

EPSS

Процентиль: 100%
0.86767
Высокий

9.9 Critical

CVSS3

Связанные уязвимости

CVSS3: 8.8
redhat
10 месяцев назад

Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to manipulate the garbage collector, trigger a use-after-free and potentially lead to remote code execution. The problem exists in all versions of Redis with Lua scripting. This issue is fixed in version 8.2.2. To workaround this issue without patching the redis-server executable is to prevent users from executing Lua scripts. This can be done using ACL to restrict EVAL and EVALSHA commands.

CVSS3: 9.9
nvd
10 месяцев назад

Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to manipulate the garbage collector, trigger a use-after-free and potentially lead to remote code execution. The problem exists in all versions of Redis with Lua scripting. This issue is fixed in version 8.2.2. To workaround this issue without patching the redis-server executable is to prevent users from executing Lua scripts. This can be done using ACL to restrict EVAL and EVALSHA commands.

CVSS3: 9.9
msrc
10 месяцев назад

Redis Lua Use-After-Free may lead to remote code execution

CVSS3: 9.9
debian
10 месяцев назад

Redis is an open source, in-memory database that persists on disk. Ver ...

CVSS3: 9.9
github
10 месяцев назад

Lua Use-After-Free may lead to remote code execution

EPSS

Процентиль: 100%
0.86767
Высокий

9.9 Critical

CVSS3

Уязвимость CVE-2025-49844