yocto ▾
›
master ▾
›
vulnerability
›
CVE-2022-0543
Component Overview
Vulnerability Overview
Name
CVE-2022-0543
Source
NVD (
link
)
Debian (
link
)
Description
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.
CWEs
CWE-862
CWE-862
Published Date
Feb 18, 2022
Updated Date
Jun 17, 2026
Workaround
-
Advisories
http://packetstormsecurity.com/files/166885/Redis-Lua-Sandbox-Escape.html
Exploit
https://bugs.debian.org/1005787
Issue Tracking
https://lists.debian.org/debian-security-announce/2022/msg00048.html
Mailing List
https://security.netapp.com/advisory/ntap-20220331-0004/
Third Party Advisory
https://www.debian.org/security/2022/dsa-5081
Mailing List
https://www.ubercomp.com/posts/2022-01-20_redis_on_debian_rce
Third Party Advisory
http://packetstormsecurity.com/files/166885/Redis-Lua-Sandbox-Escape.html
Exploit
https://bugs.debian.org/1005787
Issue Tracking
https://lists.debian.org/debian-security-announce/2022/msg00048.html
Mailing List
https://security.netapp.com/advisory/ntap-20220331-0004/
Third Party Advisory
https://www.debian.org/security/2022/dsa-5081
Mailing List
https://www.ubercomp.com/posts/2022-01-20_redis_on_debian_rce
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-0543
US Government Resource
Analysis
#
Affected Component
Analysis
redis
False Positive
Vulnerability Ratings
#
10
CVSSv31
10
CVSSv31
10
CVSSv2
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
redis
buildroot
2025.02.x
7.2.14
Not Affected
redis
buildroot
master
8.8.0
Not Affected
redis
openwrt
master
6.2.14-r1
Not Affected
redis
openwrt
openwrt-25.12
6.2.14-r1
Not Affected
redis
yocto
kirkstone
7.0.15
Not Affected
redis
yocto
scarthgap
7.2.12
False Positive