Executive brief
A packaging issue in Debian-specific Redis builds allows for a Lua sandbox escape. This vulnerability enables remote attackers to execute arbitrary code on the host system via the Redis Lua interpreter.
Affected products
- Debian Redis Server 9.0, 10.0, 11.0
- Canonical Ubuntu Linux 20.04, 21.10
Timeline
- 2022-01-20: disclosed: Initial discovery/post by Ubercomp
- 2022-03-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-28: advisory: NVD publication date
- 2022-03-28: exploited: Confirmed exploited in the wild per CISA KEV catalog