← volver
CVE-2025-49844criticalexplotación observadaCWE-416

Redis Lua Use-After-Free may lead to remote code execution

100Vexday Risk Score

Corrige ahora. Ella explotación observada por VulnCheck y tiene exploit funcional público.

ssvc Actcvss 10epss 82%
de la publicación al arma0 días
Publicada en NVD3 oct
1ª PoC13 abr
VulnCheck+81d
probabilidad de explotación
82%top 1% de las CVE
explotación observada
síVulnCheck
16 exploit(s) público(s)
Lo que declaran los fabricantes (VEX)

Declaraciones oficiales de los fabricantes en formato CSAF/VEX: si su producto está afectado, ya corregido o descartado — y por qué. Es afirmación del fabricante, no juicio de Vexday.

Corregido
16 productos (298 componentes)
Red Hat Enterprise Linux AppStream (v. 9) · Red Hat Enterprise Linux AppStream EUS (v.9.4) · Red Hat Enterprise Linux AppStream (v. 10) · Red Hat Enterprise Linux AppStream E4S (v.9.0) · Red Hat Enterprise Linux AppStream E4S (v.9.2) · y otros 11
No afectado
17 productos (261 componentes) — porque el código vulnerable no está presente en el producto
Red Hat OpenStack Platform 13 (Queens) · Red Hat OpenShift GitOps 1.17 · Red Hat OpenShift GitOps 1.18 · Red Hat Ansible Automation Platform 2 · Red Hat OpenShift GitOps 1.16 · y otros 12
Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lua script to manipulate the garbage collector, trigger a use-after-free and potentially lead to remote code execution. The problem exists in all versions of Redis with Lua scripting. This issue is fixed in version 8.2.2. To workaround this issue without patching the redis-server executable is to prevent users from executing Lua scripts. This can be done using ACL to restrict EVAL and EVALSHA commands.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Productos afectados
redis · redis
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.