Junglewise Threat Intelligence

CVE-2022-0543: Debian-specific Redis Server Lua Sandbox Escape Vulnerability

CVE-2022-0543 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2022-03-28

Vendors: Canonical, Debian.

Executive brief

A packaging issue in Debian-specific Redis builds allows for a Lua sandbox escape. This vulnerability enables remote attackers to execute arbitrary code on the host system via the Redis Lua interpreter.

Affected products

  • Debian Redis Server 9.0, 10.0, 11.0
  • Canonical Ubuntu Linux 20.04, 21.10

Timeline

  • 2022-01-20: disclosed: Initial discovery/post by Ubercomp
  • 2022-03-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-28: advisory: NVD publication date
  • 2022-03-28: exploited: Confirmed exploited in the wild per CISA KEV catalog