Vulnerability record · CVE-2018-11218 · published 17 June 2018
CVE-2018-11218: Redis cmsgpack Lua library stack buffer overflow memory corruption
Redislabs · Redis
Redis versions before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 contain a stack-based buffer overflow in the cmsgpack library used by the Lua scripting subsystem. The flaw is an out-of-bounds write (CWE-787) that corrupts memory and can crash or compromise the Redis process. It matters because Redis is widely deployed and the CVSS 3.0 base score is 9.8 critical.
Description
Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 because of stack-based buffer overflows.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 critical with network reachability, no privileges or interaction required, high EPSS, and public exploit references make this a top remediation priority.
What it is
Redis versions before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 contain a stack-based buffer overflow in the cmsgpack library used by the Lua scripting subsystem. The flaw is an out-of-bounds write (CWE-787) that corrupts memory and can crash or compromise the Redis process. It matters because Redis is widely deployed and the CVSS 3.0 base score is 9.8 critical.
Impact
An attacker can corrupt memory in the Redis process, leading to a crash or potentially arbitrary code execution in the context of the Redis server. The CVSS vector rates confidentiality, integrity, and availability impact as high.
Attack surface
The CVSS vector is network-reachable with no privileges and no user interaction (AV:N/AC:L/PR:N/UI:N), so the vulnerable Lua/cmsgpack path is reached over the network. No authentication is required per the vector, though the record does not state whether the affected command path is exposed only to authenticated clients in default configurations.
Exploitation
CISA KEV does not list this CVE, but EPSS is 0.59006 (99.067th percentile), indicating high predicted exploitation activity. Multiple references are tagged Exploit, including the antirez advisory and a Redis commit, so public exploit material exists.
What to do
- Upgrade Redis to 3.2.12, 4.0.10, 5.0 RC2 or later, or apply the vendor patches referenced in the record.
- Apply distribution and vendor errata (Red Hat RHSA-2019:0052, RHSA-2019:0094, RHSA-2019:1860; Debian DSA-4230; Oracle CPU April 2019; Gentoo GLSA 201908-04).
- Restrict network access to Redis so only trusted hosts and applications can reach the service.
- Disable or avoid untrusted Lua scripting and cmsgpack use where the workload does not require it.
- Monitor for and apply any later Redis security updates that supersede these fixed versions.
Detection
- Monitor Redis logs and process health for crashes, restarts, or abnormal termination that could indicate memory corruption.
- Alert on unexpected or malformed EVAL/EVALSHA or cmsgpack-related Lua script activity from untrusted clients.
- Track Redis version inventory and flag instances still below 3.2.12, 4.0.10, or 5.0 RC2.
- Watch for network connections to Redis from hosts outside the expected client set.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2018-11218 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-11218), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.