Impact
An authenticated user may use a specially crafted Lua script to trigger a stack buffer overflow in the bit library, which may potentially lead to remote code execution.
The problem exists in all versions of Valkey with Lua scripting.
Patches
The problem is fixed in Valkey 7.2.7 and Valkey 8.0.1.
Credit
The problem was reported by ankki-zsyang, Shenzhen Ankki Technologies Co.Ltd.
Impact
An authenticated user may use a specially crafted Lua script to trigger a stack buffer overflow in the bit library, which may potentially lead to remote code execution.
The problem exists in all versions of Valkey with Lua scripting.
Patches
The problem is fixed in Valkey 7.2.7 and Valkey 8.0.1.
Credit
The problem was reported by ankki-zsyang, Shenzhen Ankki Technologies Co.Ltd.