Redis Lua Use-After-Free may lead to remote code execution
100Vexday Risk Score
Corrige ahora. Ella explotación observada por VulnCheck y tiene exploit funcional público.
ssvc Actcvss 10epss 82%
de la publicación al arma0 días
Publicada en NVD3 oct
1ª PoC13 abr
VulnCheck+81d
probabilidad de explotación
82%top 1% de las CVE
explotación observada
síVulnCheck
16 exploit(s) público(s)
Lo que declaran los fabricantes (VEX)
Declaraciones oficiales de los fabricantes en formato CSAF/VEX: si su producto está afectado, ya corregido o descartado — y por qué. Es afirmación del fabricante, no juicio de Vexday.
Red Hatdocumento VEX ↗
Corregido
16 productos (298 componentes)
Red Hat Enterprise Linux AppStream (v. 9) · Red Hat Enterprise Linux AppStream EUS (v.9.4) · Red Hat Enterprise Linux AppStream (v. 10) · Red Hat Enterprise Linux AppStream E4S (v.9.0) · Red Hat Enterprise Linux AppStream E4S (v.9.2) · y otros 11
No afectado
17 productos (261 componentes) — porque el código vulnerable no está presente en el producto
Red Hat OpenStack Platform 13 (Queens) · Red Hat OpenShift GitOps 1.17 · Red Hat OpenShift GitOps 1.18 · Red Hat Ansible Automation Platform 2 · Red Hat OpenShift GitOps 1.16 · y otros 12
Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to manipulate the garbage collector, trigger a use-after-free and potentially lead to remote code execution. The problem exists in all versions of Redis with Lua scripting. This issue is fixed in version 8.2.2. To workaround this issue without patching the redis-server executable is to prevent users from executing Lua scripts. This can be done using ACL to restrict EVAL and EVALSHA commands.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Productos afectados
redis · redisPoCs públicas encontradas — 16
githubgithub.com/saneki/cve-2025-49844★ 25githubgithub.com/ksnnd32/redis_exploit★ 1githubgithub.com/Zain3311/CVE-2025-49844★ 1githubgithub.com/Cilectiy/CVE-2025-49844★ 1githubgithub.com/open-flaw/CVE-2025-49844★ 0githubgithub.com/zbyszkok/CVE-2025-49844-RediShell-AI-made-Revshell★ 0githubgithub.com/0xBlackash/CVE-2025-49844★ 0githubgithub.com/cc3305/CVE-2025-49844★ 0vulncheckvulncheck.com/xdb/33a716ddae72no verificadovulncheckvulncheck.com/xdb/dfd27944e627no verificadovulncheckvulncheck.com/xdb/307176e060ddno verificadovulncheckvulncheck.com/xdb/ec5b732729feno verificadovulncheckvulncheck.com/xdb/d8be47ccfd47no verificadovulncheckvulncheck.com/xdb/f2e2e0f8c893no verificadovulncheckvulncheck.com/xdb/8106ff045c2bno verificadocve_referencegithub.com/lastvocher/redis-CVE-2025-49844no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
Referencias
https://github.com/lastvocher/redis-CVE-2025-49844https://github.com/redis/redis/commit/d5728cb5795c966c5b5b1e0f0ac576a7e69af539https://github.com/redis/redis/releases/tag/8.2.2https://github.com/redis/redis/security/advisories/GHSA-4789-qfc9-5f9qhttp://www.openwall.com/lists/oss-security/2025/10/07/2