Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled or can be disabled, which may lead to remote code execution. A workaround is to prevent users from executing Lua scripts or avoid using replicas where replica-read-only is disabled. This is patched in version 8.6.3.
{
"binaries": [
{
"binary_version": "5:7.0.15-1ubuntu0.24.04.4",
"binary_name": "redis"
},
{
"binary_version": "5:7.0.15-1ubuntu0.24.04.4",
"binary_name": "redis-sentinel"
},
{
"binary_version": "5:7.0.15-1ubuntu0.24.04.4",
"binary_name": "redis-server"
},
{
"binary_version": "5:7.0.15-1ubuntu0.24.04.4",
"binary_name": "redis-tools"
}
]
}{
"binaries": [
{
"binary_version": "5:8.0.2-3ubuntu0.25.10.1",
"binary_name": "redis"
},
{
"binary_version": "5:8.0.2-3ubuntu0.25.10.1",
"binary_name": "redis-sentinel"
},
{
"binary_version": "5:8.0.2-3ubuntu0.25.10.1",
"binary_name": "redis-server"
},
{
"binary_version": "5:8.0.2-3ubuntu0.25.10.1",
"binary_name": "redis-tools"
}
]
}{
"binaries": [
{
"binary_version": "5:4.0.9-1ubuntu0.2+esm7",
"binary_name": "redis"
},
{
"binary_version": "5:4.0.9-1ubuntu0.2+esm7",
"binary_name": "redis-sentinel"
},
{
"binary_version": "5:4.0.9-1ubuntu0.2+esm7",
"binary_name": "redis-server"
},
{
"binary_version": "5:4.0.9-1ubuntu0.2+esm7",
"binary_name": "redis-tools"
}
]
}{
"binaries": [
{
"binary_version": "5:5.0.7-2ubuntu0.1+esm4",
"binary_name": "redis"
},
{
"binary_version": "5:5.0.7-2ubuntu0.1+esm4",
"binary_name": "redis-sentinel"
},
{
"binary_version": "5:5.0.7-2ubuntu0.1+esm4",
"binary_name": "redis-server"
},
{
"binary_version": "5:5.0.7-2ubuntu0.1+esm4",
"binary_name": "redis-tools"
}
]
}{
"binaries": [
{
"binary_version": "5:6.0.16-1ubuntu1.1+esm1",
"binary_name": "redis"
},
{
"binary_version": "5:6.0.16-1ubuntu1.1+esm1",
"binary_name": "redis-sentinel"
},
{
"binary_version": "5:6.0.16-1ubuntu1.1+esm1",
"binary_name": "redis-server"
},
{
"binary_version": "5:6.0.16-1ubuntu1.1+esm1",
"binary_name": "redis-tools"
}
]
}