Back to Vulnerability Directory
HIGHFixed upstream

CVE-2024-31449

Redis Lua bit library stack buffer overflow may lead to remote code execution

Technology

Redis

CVSS Score

8.8 / 10.0

Affected Versions

2.8.18 and later, before 6.2.16, 7.2.6 and 7.4.1

Upstream Fix

6.2.16, 7.2.6, 7.4.1

Published

October 7, 2024

OSSeva Coverage

Fixed upstream

Description

An authenticated user can use a crafted Lua script to trigger a stack buffer overflow in the bit library, which may lead to remote code execution. The advisory lists no workaround.

Upstream record: NVD · CVE.org

Is your Redis deployment affected?

If you're running 2.8.18 and later, before 6.2.16, 7.2.6 and 7.4.1, you need this patch. Book a discovery call to get covered.