Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 because of stack-based buffer overflows.
{
"unresolved_ranges": [
{
"vendor_product": "debian:debian_linux",
"source": "CPE_STRING",
"extracted_events": [
{
"introduced": "9.0"
},
{
"last_affected": "9.0"
}
],
"cpes": [
"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"
]
},
{
"vendor_product": "oracle:communications_operations_monitor",
"source": "CPE_STRING",
"extracted_events": [
{
"introduced": "3.4"
},
{
"last_affected": "3.4"
},
{
"introduced": "4.0"
},
{
"last_affected": "4.0"
}
],
"cpes": [
"cpe:2.3:a:oracle:communications_operations_monitor:3.4:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:communications_operations_monitor:4.0:*:*:*:*:*:*:*"
]
},
{
"vendor_product": "redhat:openstack",
"source": "CPE_STRING",
"extracted_events": [
{
"introduced": "10"
},
{
"last_affected": "10"
},
{
"introduced": "13"
},
{
"last_affected": "13"
}
],
"cpes": [
"cpe:2.3:a:redhat:openstack:10:*:*:*:*:*:*:*",
"cpe:2.3:a:redhat:openstack:13:*:*:*:*:*:*:*"
]
}
]
}[
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"16911033430593959714276436254180720746",
"118647126258626533724160258916734123784",
"266997613451356111695635551196073534977"
],
"threshold": 0.9
},
"id": "CVE-2018-11218-700a840d",
"target": {
"file": "deps/lua/src/lua_cmsgpack.c"
},
"source": "https://github.com/antirez/redis/commit/52a00201fca331217c3b4b8b634f6a0f57d6b7d3",
"signature_version": "v1"
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 471.0,
"function_hash": "311114601621233800883377513176254974414"
},
"id": "CVE-2018-11218-d30d5814",
"target": {
"function": "mp_pack",
"file": "deps/lua/src/lua_cmsgpack.c"
},
"source": "https://github.com/antirez/redis/commit/52a00201fca331217c3b4b8b634f6a0f57d6b7d3",
"signature_version": "v1"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-11218.json"
"2026-08-07T14:49:39Z"
{
"source": [
"CPE_RANGE",
"CPE_STRING"
],
"cpe": [
"cpe:2.3:a:redislabs:redis:*:*:*:*:*:*:*:*",
"cpe:2.3:a:redislabs:redis:5.0:rc1:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "3.2.12"
},
{
"introduced": "4.0"
},
{
"fixed": "4.0.10"
},
{
"introduced": "5.0-rc1"
},
{
"last_affected": "5.0-rc1"
}
]
}