Goal Reached Thanks to every supporter โ€” we hit 100%!

Goal: 1000 CNY ยท Raised: 1359 CNY

100%

CVE-2025-49844 โ€” AI Deep Analysis Summary

CVSS 10.0 ยท Critical

Q1What is this vulnerability? (Essence + Consequences)

๐Ÿšจ **Essence**: Redis versions โ‰ค 8.2.1 suffer from a **Use-After-Free (UAF)** bug in the Lua parser. ๐Ÿง  **Mechanism**: A crafted Lua script triggers a race condition with the Garbage Collector (GC).โ€ฆ

Q2Root Cause? (CWE/Flaw)

๐Ÿ›ก๏ธ **CWE**: CWE-416 (Use-After-Free). ๐Ÿ” **Root Cause**: The `luaY_parser` function fails to **anchor the chunk name string** on the Lua stack before invoking the lexer.โ€ฆ

Q3Who is affected? (Versions/Components)

๐Ÿ“ฆ **Vendor**: Redis (Open Source). ๐Ÿ“‰ **Affected Versions**: **Redis 8.2.1 and earlier**. โœ… **Fixed Version**: Redis 8.2.2+.โ€ฆ

Q4What can hackers do? (Privileges/Data)

๐Ÿ’ป **Privileges**: Hackers gain **Remote Code Execution (RCE)**. ๐Ÿ”“ **Impact**: Full control over the Redis server process. ๐Ÿ“‚ **Data**: Can read/write any data accessible to the Redis instance.โ€ฆ

Q5Is exploitation threshold high? (Auth/Config)

๐Ÿ”‘ **Auth Required**: **Yes**. The CVSS vector `PR:L` indicates **Privileges Required: Low**. ๐ŸŒ **Access**: Attacker needs network access and valid credentials to run Lua scripts.โ€ฆ

Q6Is there a public Exp? (PoC/Wild Exploitation)

๐Ÿ”ฅ **Public Exploits**: **YES**. Multiple PoCs exist: - `dwisiswant0/CVE-2025-49844` (Lua Parser UAF) - `raminfp/redis_exploit` (RediShell) - `srozb/reditrap` (Honeypot detection).โ€ฆ

Q7How to self-check? (Features/Scanning)

๐Ÿ” **Self-Check**: - Check Redis version (`INFO SERVER`). - Use `dwisiswant0/CVE-2025-49844` scripts to test for UAF.โ€ฆ

Q8Is it fixed officially? (Patch/Mitigation)

๐Ÿ› ๏ธ **Official Fix**: **YES**. Patched in **Redis 8.2.2**. ๐Ÿ”— **Commit**: `d5728cb` fixes the issue by pushing the chunk name to the stack before parsing. ๐Ÿ“ข **Advisory**: GHSA-4789-qfc9-5f9q confirms the fix.โ€ฆ

Q9What if no patch? (Workaround)

๐Ÿšง **No Patch Workaround**: - **Disable Lua scripting** if not needed (`lua-time-limit` or config changes). - **Restrict Network Access**: Block external access to Redis ports (6379).โ€ฆ

Q10Is it urgent? (Priority Suggestion)

โšก **Urgency**: **CRITICAL / IMMEDIATE**. ๐Ÿšจ **Priority**: P0. - CVSS 10.0 score. - Active PoCs in the wild. - RCE impact. - Easy to exploit with low privileges. ๐Ÿ“… **Timeline**: Published Oct 3, 2025. Fix available.โ€ฆ