Back to Vulnerability Directory
CRITICALFixed upstream
CVE-2018-11218
Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before…
Technology
Redis
CVSS Score
9.8 / 10.0
Affected Versions
<3.2.12; >=4.0 <4.0.10; 5.0
Upstream Fix
See upstream advisory
Published
June 17, 2018
OSSeva Coverage
Fixed upstream
Description
Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 because of stack-based buffer overflows.
Is your Redis deployment affected?
If you're running <3.2.12; >=4.0 <4.0.10; 5.0, you need this patch. Book a discovery call to get covered.