Vulnerability record · CVE-2022-0543 · published 18 February 2022
CVE-2022-0543: Debian-packaged Redis Lua sandbox escape allows remote code execution
Redis · Redis
A Debian-specific packaging flaw in Redis leaves the Lua interpreter's sandbox improperly restricted, allowing escape from the Lua sandbox. Because Redis is a network-facing key-value database, this escape can lead to remote code execution on the host. The issue is a packaging defect rather than an upstream Redis code bug, so only Debian-built packages are affected.
Description
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 10.0, confirmed exploitation in CISA KEV, and near-certain EPSS probability make this an urgent remote code execution risk.
What it is
A Debian-specific packaging flaw in Redis leaves the Lua interpreter's sandbox improperly restricted, allowing escape from the Lua sandbox. Because Redis is a network-facing key-value database, this escape can lead to remote code execution on the host. The issue is a packaging defect rather than an upstream Redis code bug, so only Debian-built packages are affected.
Impact
An attacker who can reach the Redis service can break out of the Lua sandbox and execute arbitrary code with the privileges of the Redis process. This gives full control of the Redis host, including data access and potential lateral movement.
Attack surface
Reached over the network via the Redis service, as reflected by the CVSS vector AV:N/PR:N/UI:N, meaning no authentication or user interaction is required. The flaw is triggered through Lua scripting functionality exposed by the Debian-packaged Redis build.
Exploitation
CVE-2022-0543 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-28) and has an EPSS 30-day probability of 0.99351 (99.9th percentile), with public exploit references tagged 'Exploit'. No ransomware campaign use is documented in the record.
What to do
- Apply the Debian security update (DSA-5081) or the vendor-recommended patched package for Redis immediately.
- If patching cannot be done at once, restrict network access to Redis so it is not reachable from untrusted networks.
- Require authentication and avoid exposing Redis on public interfaces; bind to localhost or trusted management networks only.
- Disable or restrict the Lua scripting interface (EVAL/EVALSHA) where it is not operationally required.
- Monitor vendor advisories for any additional affected packages or downstream products.
Detection
- Monitor Redis logs and process behavior for unexpected EVAL/EVALSHA usage or Lua script execution.
- Alert on Redis spawning child processes or making outbound network connections, which is abnormal for a database service.
- Hunt for known public exploit payloads against Redis Lua scripting in network traffic or host telemetry.
- Track unpatched Debian Redis instances in asset inventory and verify package versions against DSA-5081.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-0543 to the Known Exploited Vulnerabilities catalog on 28 March 2022 as "Debian-specific Redis Server Lua Sandbox Escape Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 18 April 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-0543 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-0543), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.