https://seclists.org/oss-sec/2025/q4/17: dis: CVE-2025-49844: Lua Use-After-Fe may lead to mote code execution
Published Oct 7, 2025
·Updated
Affected Software
1 affected component
Redis redis=
Frequently Asked Questions
1
What is the severity of CVE-2025-49844?
CVE-2025-49844 has a CVSS score of 9.9, indicating a critical severity level.
2
How do I fix CVE-2025-49844?
To fix CVE-2025-49844, update to the latest version of Redis that addresses this vulnerability.
3
What type of vulnerability is CVE-2025-49844?
CVE-2025-49844 is a Lua Use-After-Free vulnerability that may lead to remote code execution.
4
Which software is affected by CVE-2025-49844?
CVE-2025-49844 affects Redis software versions that contain the vulnerable Lua interpreter.
5
What impact does CVE-2025-49844 have on systems?
CVE-2025-49844 can allow attackers to execute arbitrary code on affected systems, compromising system integrity.