PT-2025-1017 · Redis+10 · Redis+10

P33Zy

·

Published

2024-07-18

·

Updated

2025-10-21

·

CVE-2024-46981

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Redis versions prior to 7.4.2 Redis versions prior to 7.2.7 Redis versions prior to 6.2.17
Description The issue is related to a use-after-free vulnerability in Redis, which can be exploited by manipulating the garbage collector using a specially crafted Lua script. This can potentially lead to remote code execution. An authenticated user may use this script to manipulate the garbage collector. The problem is fixed in versions 7.4.2, 7.2.7, and 6.2.17.
Recommendations For versions prior to 7.4.2, update to version 7.4.2 or later to resolve the issue. For versions prior to 7.2.7, update to version 7.2.7 or later to resolve the issue. For versions prior to 6.2.17, update to version 6.2.17 or later to resolve the issue. As a temporary workaround, consider preventing users from executing Lua scripts by restricting EVAL and EVALSHA commands using ACL to minimize the risk of exploitation.

Exploit

Fix

RCE

Integer Overflow

Heap Based Buffer Overflow

Use After Free

Weakness Enumeration

Related Identifiers

ALSA-2025:0595
ALSA-2025:0692
ALSA-2025:0693
ALSA-2025_0692
ALSA-2025_16880
ALT-PU-2025-11673
ALT-PU-2025-1294
ALT-PU-2025-13204
ALT-PU-2025-1404
ALT-PU-2025-1408
ALT-PU-2025-1851
ALT-PU-2025-9766
AZL-54969
AZL-55286
BDU:2025-00214
BDU:2025-03162
BDU:2025-03163
BIT-KEYDB-2024-46981
BIT-REDIS-2024-46981
BIT-VALKEY-2024-46981
CESA-2025_0595
CVE-2024-46981
DLA-4025-1
DSA-5856-1
GHSA-39H2-X6C4-6W4C
INFSA-2025_0595
INFSA-2025_0693
MGASA-2025-0033
OESA-2025-1157
OPENSUSE-SU-2025:14638-1
OPENSUSE-SU-2025:15293-1
OPENSUSE-SU-2025_0160-1
OPENSUSE-SU-2025_0161-1
OPENSUSE-SU-2025_0162-1
OPENSUSE-SU-2025_0163-1
RHSA-2025:0398
RHSA-2025:0399
RHSA-2025:0400
RHSA-2025:0566
RHSA-2025:0595
RHSA-2025:0640
RHSA-2025:0685
RHSA-2025:0689
RHSA-2025:0692
RHSA-2025:0693
RHSA-2025_0595
RHSA-2025_0692
RHSA-2025_0693
RLSA-2025:0595
RLSA-2025:0692
RLSA-2025:0693
SUSE-SU-2025:0081-1
SUSE-SU-2025:0160-1
SUSE-SU-2025:0161-1
SUSE-SU-2025:0162-1
SUSE-SU-2025:0163-1
SUSE-SU-2025_0160-1
SUSE-SU-2025_0161-1
SUSE-SU-2025_0162-1
SUSE-SU-2025_0163-1
USN-7321-1
USN-7359-1
ZDI-25-010

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Redis
Rocky Linux
Suse
Ubuntu