Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2018-11218

Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before…

Technology

Redis

CVSS Score

9.8 / 10.0

Affected Versions

<3.2.12; >=4.0 <4.0.10; 5.0

Upstream Fix

See upstream advisory

Published

June 17, 2018

OSSeva Coverage

Fixed upstream

Description

Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 because of stack-based buffer overflows.

Is your Redis deployment affected?

If you're running <3.2.12; >=4.0 <4.0.10; 5.0, you need this patch. Book a discovery call to get covered.