cbcvebase.
CVE-2018-11218
published 2018-06-17

CVE-2018-11218: Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 because of…

PriorityP273critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
59.42%
99.0th percentile
Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 because of stack-based buffer overflows.

Affected

13 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianredis< redis 5:4.0.10-1 (bookworm)redis 5:4.0.10-1 (bookworm)
oraclecommunications_operations_monitor
oraclecommunications_operations_monitor
redhatopenstack
redhatopenstack
redisredis>= 0 < 5:4.0.10-15:4.0.10-1
redisredis>= 0 < 5:4.0.10-15:4.0.10-1
redisredis>= 0 < 5:4.0.10-15:4.0.10-1
redisredis>= 0 < 5:4.0.10-15:4.0.10-1
redislabsredis< 3.2.123.2.12
redislabsredis
redislabsredis>= 4.0 < 4.0.104.0.10

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability resides in the cmsgpack library (lua_cmsgpack.c) within the Lua subsystem of Redis — monitor for exploitation attempts targeting Redis Lua script execution paths
  • Patch commits for CVE-2018-11218 can be used to derive pre-patch vs. post-patch behavioral differences for detection rule development
  • Related exploitation technique (Redis replication abuse for code execution) uses Redis master-slave replication to deliver a malicious extension — monitor for unexpected SLAVEOF or REPLICAOF commands and unusual .so module loads on Redis instances
  • ·Only Redis versions before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 are affected; patched versions are not vulnerable
  • ·Red Hat Enterprise Linux 8 ships a non-affected version of Redis; RHEL OpenStack Platform packages are marked 'Will not fix' — assess exposure accordingly
  • ·Debian fixed the vulnerability in package version 5:4.0.10-1 across all supported releases (bookworm, bullseye, forky, sid, trixie)

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.