← Vulnerability feed

Vulnerability record · CVE-2022-0543 · published 18 February 2022

CVE-2022-0543: Debian-packaged Redis Lua sandbox escape allows remote code execution

Redis · Redis

A Debian-specific packaging flaw in Redis leaves the Lua interpreter's sandbox improperly restricted, allowing escape from the Lua sandbox. Because Redis is a network-facing key-value database, this escape can lead to remote code execution on the host. The issue is a packaging defect rather than an upstream Redis code bug, so only Debian-built packages are affected.

10.0 CVSS 3.1 Critical CISA KEV since 28 Mar 2022 EPSS 99% · top 0.1% CWE-862 · Missing authorization
10.0CVSS 3.1 base score, v2 10.0
99%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
13References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 10.0, confirmed exploitation in CISA KEV, and near-certain EPSS probability make this an urgent remote code execution risk.

What it is

A Debian-specific packaging flaw in Redis leaves the Lua interpreter's sandbox improperly restricted, allowing escape from the Lua sandbox. Because Redis is a network-facing key-value database, this escape can lead to remote code execution on the host. The issue is a packaging defect rather than an upstream Redis code bug, so only Debian-built packages are affected.

Impact

An attacker who can reach the Redis service can break out of the Lua sandbox and execute arbitrary code with the privileges of the Redis process. This gives full control of the Redis host, including data access and potential lateral movement.

Attack surface

Reached over the network via the Redis service, as reflected by the CVSS vector AV:N/PR:N/UI:N, meaning no authentication or user interaction is required. The flaw is triggered through Lua scripting functionality exposed by the Debian-packaged Redis build.

Exploitation

CVE-2022-0543 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-28) and has an EPSS 30-day probability of 0.99351 (99.9th percentile), with public exploit references tagged 'Exploit'. No ransomware campaign use is documented in the record.

What to do

  • Apply the Debian security update (DSA-5081) or the vendor-recommended patched package for Redis immediately.
  • If patching cannot be done at once, restrict network access to Redis so it is not reachable from untrusted networks.
  • Require authentication and avoid exposing Redis on public interfaces; bind to localhost or trusted management networks only.
  • Disable or restrict the Lua scripting interface (EVAL/EVALSHA) where it is not operationally required.
  • Monitor vendor advisories for any additional affected packages or downstream products.

Detection

  • Monitor Redis logs and process behavior for unexpected EVAL/EVALSHA usage or Lua script execution.
  • Alert on Redis spawning child processes or making outbound network connections, which is abnormal for a database service.
  • Hunt for known public exploit payloads against Redis Lua scripting in network traffic or host telemetry.
  • Track unpatched Debian Redis instances in asset inventory and verify package versions against DSA-5081.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-0543 to the Known Exploited Vulnerabilities catalog on 28 March 2022 as "Debian-specific Redis Server Lua Sandbox Escape Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 18 April 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-0543 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2025-49844Redis Lua scripting use-after-free enables remote code executionRedis versions 8.2.1 and below contain a use-after-free in the Lua scripting engine. An authenticated user can supply a crafted Lua script that manip…EPSS 82%analysed9.8CVE-2025-27151Redis improper input validation vulnerabilityRedis is an open source, in-memory database that persists on disk. In versions starting from 7.0.0 to before 8.0.2, a stack-based buffer overflow exi…EPSS 0.95%9.8CVE-2024-46981Redis use after free vulnerabilityRedis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to manipulate the gar…EPSS 8.2%9.8CVE-2022-3734Redis untrusted search path vulnerabilityA vulnerability was found in a port or fork of Redis. It has been declared as critical. This vulnerability affects unknown code in the library C:/Pro…EPSS 0.65%9.8CVE-2022-35951Redis integer overflow vulnerabilityRedis is an in-memory database that persists on disk. Versions 7.0.0 and above, prior to 7.0.5 are vulnerable to an Integer Overflow. Executing an `X…EPSS 3.9%8.8CVE-2025-46817Redis integer overflow vulnerabilityRedis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lu…EPSS 3.8%8.8CVE-2024-31449Redis improper input validation vulnerabilityRedis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to trigger a stack bu…EPSS 4.5%8.8CVE-2022-24834Redis heap-based buffer overflow vulnerabilityRedis is an in-memory database that persists on disk. A specially crafted Lua script executing in Redis can trigger a heap overflow in the cjson libr…EPSS 41%

Source: NIST National Vulnerability Database (record CVE-2022-0543), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.