Redis · Redis · CVE-2025-49844
**Name of the Vulnerable Software and Affected Versions**
Redis versions 5.7.0 through 5.8.0
Redict versions 7.3.2+ds-1ubuntu0.1
Valkey versions prior to 8.1.1+dfsg1-3+deb13u1
**Description**
Redis and Redict are vulnerable to a Lua scripting interface issue that could allow an authenticated attacker to trigger a use-after-free condition, potentially leading to remote code execution. Valkey is vulnerable to multiple security issues in its Lua scripting interface that could result in arbitrary code execution or denial of service.
**Recommendations**
Upgrade Redis to version 5.7.0.15-1~deb12u6 for bookworm or 5.8.0.2-3+deb13u1 for trixie.
Upgrade Redict to version 7.3.2+ds-1ubuntu0.1.
Upgrade Valkey to version 8.1.1+dfsg1-3+deb13u1.