CVE-2022-0543: Debian-specific Redis Server Lua Sandbox Escape Vulnerability
Redis is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.
Other sources
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/redisto a version that resolves this vulnerability.Fixed in 5:6.0.16-1+deb11u2Fixed in 5:5.0.14-1+deb10u2Fixed in 5:6.0.16-2Fixed in 5:7.0~rc2-2 - Upgrade
Upgrade
debian/redisto a version that resolves this vulnerability.Fixed in 5:5.0.14-1+deb10u2Fixed in 5:5.0.14-1+deb10u5Fixed in 5:6.0.16-1+deb11u2Fixed in 5:7.0.11-1Fixed in 5:7.0.14-1
Event History
Frequently Asked Questions
What is the vulnerability ID for this Redis Server vulnerability?
The vulnerability ID for this Redis Server vulnerability is CVE-2022-0543.
What is the severity of CVE-2022-0543?
CVE-2022-0543 has a severity level of critical.
What is the affected software for CVE-2022-0543?
The affected software for CVE-2022-0543 includes Redis Debian-specific Redis Servers and Redis.
How can remote code execution be achieved with CVE-2022-0543?
Remote code execution can be achieved with CVE-2022-0543 through a Debian-specific Lua sandbox escape.
How can I fix the vulnerability CVE-2022-0543?
To fix the vulnerability CVE-2022-0543, update the Redis server to version 5:6.0.16-1+deb11u2, 5:5.0.14-1+deb10u2, 5:6.0.16-2, or 5:7.0~rc2-2.