Количество 20
Количество 20
GHSA-8ghh-qpmp-7826
Lua Use-After-Free may lead to remote code execution
CVE-2026-23631
Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled or can be disabled, which may lead to remote code execution. A workaround is to prevent users from executing Lua scripts or avoid using replicas where replica-read-only is disabled. This is patched in version 8.6.3.
CVE-2026-23631
Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled or can be disabled, which may lead to remote code execution. A workaround is to prevent users from executing Lua scripts or avoid using replicas where replica-read-only is disabled. This is patched in version 8.6.3.
CVE-2026-23631
Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled or can be disabled, which may lead to remote code execution. A workaround is to prevent users from executing Lua scripts or avoid using replicas where replica-read-only is disabled. This is patched in version 8.6.3.
CVE-2026-23631
redis-server Lua use-after-free may allow remote code execution
CVE-2026-23631
Redis is an in-memory data structure store. In all versions of redis-s ...
SUSE-SU-2026:2100-1
Security update for redis7
SUSE-SU-2026:2097-1
Security update for redis7
ROS-20260708-73-0035
Уязвимость valkey
BDU:2026-06451
Уязвимость интерпретатора скриптов Lua системы управления базами данных (СУБД) Redis, позволяющая нарушителю выполнить произвольный код
SUSE-SU-2026:2099-1
Security update for redis
SUSE-SU-2026:1950-1
Security update for valkey
SUSE-SU-2026:1949-1
Security update for valkey
RLSA-2026:25925
Important: valkey security update
RLSA-2026:25219
Important: redis:7 security update
RLSA-2026:25216
Important: valkey security update
ELSA-2026-25925
ELSA-2026-25925: valkey security update (IMPORTANT)
ELSA-2026-25219
ELSA-2026-25219: redis:7 security update (IMPORTANT)
ELSA-2026-25216
ELSA-2026-25216: valkey security update (IMPORTANT)
openSUSE-SU-2026:20776-1
Security update for valkey
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-8ghh-qpmp-7826 Lua Use-After-Free may lead to remote code execution | 2% Низкий | 3 месяца назад | ||
CVE-2026-23631 Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled or can be disabled, which may lead to remote code execution. A workaround is to prevent users from executing Lua scripts or avoid using replicas where replica-read-only is disabled. This is patched in version 8.6.3. | CVSS3: 8.1 | 2% Низкий | 3 месяца назад | |
CVE-2026-23631 Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled or can be disabled, which may lead to remote code execution. A workaround is to prevent users from executing Lua scripts or avoid using replicas where replica-read-only is disabled. This is patched in version 8.6.3. | CVSS3: 8.8 | 2% Низкий | 3 месяца назад | |
CVE-2026-23631 Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled or can be disabled, which may lead to remote code execution. A workaround is to prevent users from executing Lua scripts or avoid using replicas where replica-read-only is disabled. This is patched in version 8.6.3. | CVSS3: 8.1 | 2% Низкий | 3 месяца назад | |
CVE-2026-23631 redis-server Lua use-after-free may allow remote code execution | 2% Низкий | около 2 месяцев назад | ||
CVE-2026-23631 Redis is an in-memory data structure store. In all versions of redis-s ... | CVSS3: 8.1 | 2% Низкий | 3 месяца назад | |
SUSE-SU-2026:2100-1 Security update for redis7 | 2 месяца назад | |||
SUSE-SU-2026:2097-1 Security update for redis7 | 2 месяца назад | |||
ROS-20260708-73-0035 Уязвимость valkey | CVSS3: 8.1 | 2% Низкий | 25 дней назад | |
BDU:2026-06451 Уязвимость интерпретатора скриптов Lua системы управления базами данных (СУБД) Redis, позволяющая нарушителю выполнить произвольный код | CVSS3: 8.1 | 2% Низкий | 3 месяца назад | |
SUSE-SU-2026:2099-1 Security update for redis | 2 месяца назад | |||
SUSE-SU-2026:1950-1 Security update for valkey | 3 месяца назад | |||
SUSE-SU-2026:1949-1 Security update for valkey | 3 месяца назад | |||
RLSA-2026:25925 Important: valkey security update | около 2 месяцев назад | |||
RLSA-2026:25219 Important: redis:7 security update | около 2 месяцев назад | |||
RLSA-2026:25216 Important: valkey security update | около 2 месяцев назад | |||
ELSA-2026-25925 ELSA-2026-25925: valkey security update (IMPORTANT) | около 1 месяца назад | |||
ELSA-2026-25219 ELSA-2026-25219: redis:7 security update (IMPORTANT) | около 1 месяца назад | |||
ELSA-2026-25216 ELSA-2026-25216: valkey security update (IMPORTANT) | 17 дней назад | |||
openSUSE-SU-2026:20776-1 Security update for valkey | 3 месяца назад |
Уязвимостей на страницу