Ò»¡¢Îó²î¸ÅÊö
Îó²îÃû³Æ | Redis Lua ¾ç±¾ÒýÇæÔ¶³Ì´úÂëÖ´ÐÐÎó²î |
CVE ID | CVE-2025-49844 |
Îó²îÀàÐÍ | RCE | ·¢Ã÷ʱ¼ä | 2025-10-9 |
Îó²îÆÀ·Ö | 9.9 | Îó²îÆ·¼¶ | ÑÏÖØ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ʹÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»ÐèÒª |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | δ·¢Ã÷ |
RedisÊÇÒ»¸ö¿ªÔ´µÄÄÚ´æÊý¾Ý½á¹¹´æ´¢ÏµÍ³£¬£¬ÆÕ±éÓ¦ÓÃÓÚ»º´æ¡¢ÐÂÎÅÐÐÁС¢ÊµÊ±ÆÊÎöµÈ³¡¾°¡£¡£¡£¡£ËüÖ§³Ö¶àÖÖÊý¾Ý½á¹¹£¬£¬Èç×Ö·û´®¡¢¹þÏ£¡¢ÁÐ±í¡¢ÜöÝÍ¡¢ÓÐÐòÜöÝ͵ȣ¬£¬²¢Ìṩ¸»ºñµÄ²Ù×÷ÏÂÁî¡£¡£¡£¡£Redis¾ßÓиßÐÔÄÜ¡¢ÎÞаÐԺͳ¤ÆÚ»¯ÄÜÁ¦£¬£¬Êý¾Ý¿ÉÒÔÉúÑÄÔÚÄÚ´æÖУ¬£¬°´ÆÚ»òƾ֤ÐèÇóͬ²½µ½´ÅÅÌ¡£¡£¡£¡£ËüÖ§³ÖÖ÷´Ó¸´ÖÆ¡¢·ÖÇøºÍ¸ß¿ÉÓÃÐÔÉèÖ㬣¬³£ÓÃÓÚÌá¸ßϵͳÏìÓ¦ËÙÂʺͿÉÀ©Õ¹ÐÔ¡£¡£¡£¡£ÓÉÓÚÆä¸ßЧµÄ¶ÁÈ¡ºÍдÈëÐÔÄÜ£¬£¬Redis³ÉΪÏÖ´úÂþÑÜʽϵͳÖв»¿É»òȱµÄ×é¼þÖ®Ò»¡£¡£¡£¡£
2025Äê10ÔÂ9ÈÕ£¬£¬ÄϹ¬NGÓéÀÖ¼¯ÍÅVSRC¼à²âµ½RedisÖеÄÒ»¸öÑÏÖØÎó²î£¬£¬±£´æÓÚÆäLua¾ç±¾ÒýÇæÖС£¡£¡£¡£¸ÃÎó²îÔ´ÓÚRedisÔÚ´¦Öóͷ£Lua¾ç±¾Ê±µÄÄÚ´æÖÎÀíÎÊÌ⣬£¬ÏêϸÌåÏÖΪ¡°use-after-free¡±¹ýʧ¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÈ«ÐĽṹµÄLua¾ç±¾£¬£¬Ê¹ÓÃRedisµÄÀ¬»ø½ÓÄÉ»úÖÆÊÍ·ÅÈÔ±»ÒýÓõÄÄڴ棬£¬µ¼ÖÂÄÚ´æ±»ÖØÓò¢Ö´ÐжñÒâ´úÂ룬£¬½ø¶øÊµÏÖÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¡£¡£¡£¡£¹¥»÷ÕßʹÓøÃÎó²î¿É»ñµÃRedisÖ÷»úµÄÍêÈ«¿ØÖÆÈ¨ÏÞ£¬£¬ÑÏÖØÍþÐ²ÔÆÇéÐκÍÃô¸ÐÊý¾ÝµÄÇå¾²¡£¡£¡£¡£
¶þ¡¢Ó°Ïì¹æÄ£
Èý¡¢Çå¾²²½·¥
3.1 Éý¼¶°æ±¾
Redis ¹Ù·½ÒÑÐû²¼ÐÞ¸´²¹¶¡£¬£¬ÒÔÐÞ¸´¸ÃÎó²î¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£ºhttps://github.com/redis/redis/releases/
3.2 ÔÝʱ²½·¥
ÔÝÎÞ¡£¡£¡£¡£
3.3 ͨÓý¨Òé
? °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬ïÔÌϵͳÎó²î£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£? ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬ïÔ̽«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬ïÔ̹¥»÷Ãæ¡£¡£¡£¡£? ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£? ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔÔò£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£? ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£
3.4 ²Î¿¼Á´½Ó
https://github.com/redis/redis/security/advisories/GHSA-4789-qfc9-5f9q/https://nvd.nist.gov/vuln/detail/CVE-2025-49844