Skip to content

[CORRUPTED] Synthetic Benchmark PR #14485 - Update unstable with CVE-2025-49844, CVE-2025-46818, CVE-2025-46819, CVE-2025-46817#30

Open
bar-qodo wants to merge 5 commits intobase_pr_14485_20260113_2713from
corrupted_pr_14485_20260113_2713
Open

[CORRUPTED] Synthetic Benchmark PR #14485 - Update unstable with CVE-2025-49844, CVE-2025-46818, CVE-2025-46819, CVE-2025-46817#30
bar-qodo wants to merge 5 commits intobase_pr_14485_20260113_2713from
corrupted_pr_14485_20260113_2713

Conversation

@bar-qodo
Copy link

Benchmark PR redis#14485

Type: Corrupted (contains bugs)

Original PR Title: Update unstable with CVE-2025-49844, CVE-2025-46818, CVE-2025-46819, CVE-2025-46817
Original PR Description: cherry-pick 4 cves from 8.2.

fc9abc775 2025-06-23 Lua script may lead to integer overflow and potential RCE (CVE-2025-46817) (Ozan Tezcan)
3a1624da2 2025-06-23 LUA out-of-bound read (CVE-2025-46819) (Ozan Tezcan)
45eac0262 2025-06-23 Lua script can be executed in the context of another user (CVE-2025-46818) (Ozan Tezcan)
d5728cb57 2025-06-23 Lua script may lead to remote code execution (CVE-2025-49844) (Mincho Paskalev)

We should use rebase to merge this PR.
Original PR URL: redis#14485

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants