CVE-2018-11219: Integer Overflow
An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2, leading to a failure of bounds checking.
Other sources
Redis is vulnerable to an integer overflow in the luastruct.c:bunpack() function. A remote attacker could exploit this to cause a denial of service or have other unspecified impact.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/redisto a version that resolves this vulnerability.Fixed in 5:5.0.14-1+deb10u2Fixed in 5:5.0.14-1+deb10u4Fixed in 5:6.0.16-1+deb11u2Fixed in 5:7.0.11-1Fixed in 5:7.0.13-2Fixed in 5:7.0.14-1 - Upgrade
Upgrade
redhat/redisto a version that resolves this vulnerability.Fixed in 3.2.12 - Upgrade
Upgrade
redhat/redisto a version that resolves this vulnerability.Fixed in 4.0.10 - Upgrade
Upgrade
redhat/redisto a version that resolves this vulnerability.Fixed in 5.0
Event History
Frequently Asked Questions
What is CVE-2018-11219?
CVE-2018-11219 is an Integer Overflow issue in the struct library in the Lua subsystem in Redis.
What is the severity of CVE-2018-11219?
The severity of CVE-2018-11219 is critical with a severity value of 9.8.
Which versions of Redis are affected by CVE-2018-11219?
Redis versions before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 are affected by CVE-2018-11219.
How do I fix CVE-2018-11219?
To fix CVE-2018-11219, you should update Redis to version 3.2.12 or later.
Where can I find more information about CVE-2018-11219?
You can find more information about CVE-2018-11219 at the following references: [http://antirez.com/news/119](http://antirez.com/news/119), [http://www.securityfocus.com/bid/104552](http://www.securityfocus.com/bid/104552), [https://access.redhat.com/errata/RHSA-2019:0052](https://access.redhat.com/errata/RHSA-2019:0052)