Skip to content

Conversation

@KIMDONGYEON00
Copy link
Contributor

@KIMDONGYEON00 KIMDONGYEON00 commented Oct 14, 2025

CVE-2024-31449
Affected component/file:
lua_bit.c
CVE-2024-31449 was found in Redis, and the same behavior is reproduced in Dragonfly.
A Lua stack overflow causes a crash.
According to the Redis security advisory, this vulnerability can lead to RCE attacks

CVE-2025-29844
Affected component/file:
lparser.c
Redis versions 6.2.6 and below are vulnerable to remote code execution via a specially crafted Lua script that manipulates the garbage collector to trigger use-after-free.
Fixed in version 8.2.2. Workaround: Use ACL to restrict EVAL and EVALSHA commands.
According to the Redis security advisory, this vulnerability can lead use-after-free and potentially lead to remote code execution.

CVE-2025-46817
Affected component/file:
lbaselib.c, ltable.c
Redis versions 8.2.1 and below are vulnerable to an integer overflow via a specially crafted Lua script that can corrupt Lua/VM state and potentially lead to remote code execution (RCE). Fixed in version 8.2.2. Workaround: Use ACL to restrict EVAL and EVALSHA (and related Lua/function execution) commands.
According to the Redis security advisory.

CVE-2025-46819
Affected component/file:
llex.c
Redis versions 8.2.1 and below are vulnerable to a crafted Lua script that can trigger out-of-bounds reads or crash the server (DoS) by abusing the Lua lexer/long-string parsing; this may also lead to information disclosure depending on environment. Fixed in version 8.2.2.
According to the Redis security advisory.

They are strongly recommended to update to a safe Redis version.

Fix lua UAF bug (CVE-2025-49844 - Redishell)
Fix lua bit.tohex (CVE-2024-31449)
@KIMDONGYEON00 KIMDONGYEON00 changed the title Fix Lua remote code execution (CVE-2025-49844) Fix Redis Lua security vulnerabilities (CVE-2024-31449, CVE-2025-29844) Oct 14, 2025
@KIMDONGYEON00 KIMDONGYEON00 changed the title Fix Redis Lua security vulnerabilities (CVE-2024-31449, CVE-2025-29844) Fix Redis Lua security vulnerabilities (CVE-2024-31449, CVE-2025-29844, CVE-2025-46817, CVE-2025-46819) Oct 20, 2025
@jfb8856606 jfb8856606 merged commit d668831 into F-Stack:dev Oct 21, 2025
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants