Redis is an in-memory database that persists on disk. A specially crafted Lua script executing in Redis can trigger a heap overflow in the cjson library, and result with heap corruption and potentially remote code execution. The problem exists in all versions of Redis with Lua scripting support, starting from 2.6, and affects only authenticated and authorized users. The problem is fixed in versions 7.0.12, 6.2.13, and 6.0.20.
More Stories
workrave-1.11.0~rc.1-1.el9
FEDORA-EPEL-2025-85c41364aa Packages in this update: workrave-1.11.0~rc.1-1.el9 Update description: Unretireing the package. Read More
workrave-1.11.0~rc.1-1.fc41
FEDORA-2025-d611c8d114 Packages in this update: workrave-1.11.0~rc.1-1.fc41 Update description: Unretireing the package. Read More
workrave-1.11.0~rc.1-1.fc42
FEDORA-2025-85867bd98f Packages in this update: workrave-1.11.0~rc.1-1.fc42 Update description: Unretireing the package. Read More
workrave-1.11.0~rc.1-1.fc40
FEDORA-2025-2d5726abb8 Packages in this update: workrave-1.11.0~rc.1-1.fc40 Update description: Unretireing the package. Read More
trunk-0.21.13-1.fc41
FEDORA-2025-a265e06eb2 Packages in this update: trunk-0.21.13-1.fc41 Update description: Update Trunk to v0.21.13 Read More
trunk-0.21.13-1.fc42
FEDORA-2025-3854530fd9 Packages in this update: trunk-0.21.13-1.fc42 Update description: Update Trunk to v0.21.13 Read More