Skip to content

CVE-2025-49844

CVE

Threat entity extracted from intelligence sources

Frequency
9
occurrences
First Seen
November 3, 2025
Last Seen
September 4, 2026
API
Exploited in Wild
—
Ransomware Use
—
Public Exploits
—
Attack Vector
—

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

CVE-2025-49844 is a critical use-after-free vulnerability in the Redis Lua interpreter, affecting all versions up to 8.2.1. Authenticated attackers can exploit this flaw by sending a crafted EVAL command that manipulates the garbage collector, potentially leading to remote code execution. The vulner...

Dell has released two security updates (DSA-2025-434 and DSA-2025-435) addressing multiple vulnerabilities in PowerFlex Rack and Appliance systems. The updates cover numerous CVEs, including critical vulnerabilities in third-party components affecting Dell PowerEdge servers, iDRAC, and VMware produc...

A series of vulnerabilities have been identified in Redis and Lua, affecting Ubuntu versions 16.04 to 24.04 LTS. The most critical issue, CVE-2025-49844, allows remote attackers to exploit specially crafted Lua scripts, potentially leading to denial of service or arbitrary code execution. This vulne...

A significant vulnerability (CVE-2025-49844) has been identified in the Lua parser used in Ubuntu 16.04. This flaw allows remote attackers to craft malicious Lua scripts that can crash the Lua interpreter or execute arbitrary code under the user's login. The vulnerability stems from improper handlin...

Public Exploits

Checking GitHub for proof-of-concept code…