This is a summary of the AI-generated 10-question deep analysis. The full version (longer answers, follow-up Q&A, related CVEs) requires login.
Read the full analysis โ
Q1What is this vulnerability? (Essence + Consequences)
๐จ **Essence**: Redis versions โค 8.2.1 suffer from a **Use-After-Free (UAF)** bug in the Lua parser. ๐ง **Mechanism**: A crafted Lua script triggers a race condition with the Garbage Collector (GC).โฆ
๐ก๏ธ **CWE**: CWE-416 (Use-After-Free). ๐ **Root Cause**: The `luaY_parser` function fails to **anchor the chunk name string** on the Lua stack before invoking the lexer.โฆ
๐ป **Privileges**: Hackers gain **Remote Code Execution (RCE)**. ๐ **Impact**: Full control over the Redis server process. ๐ **Data**: Can read/write any data accessible to the Redis instance.โฆ
๐ ๏ธ **Official Fix**: **YES**. Patched in **Redis 8.2.2**. ๐ **Commit**: `d5728cb` fixes the issue by pushing the chunk name to the stack before parsing. ๐ข **Advisory**: GHSA-4789-qfc9-5f9q confirms the fix.โฆ