{"id":"CVE-2021-32626","details":"Redis is an open source, in-memory database that persists on disk. In affected versions specially crafted Lua scripts executing in Redis can cause the heap-based Lua stack to be overflowed, due to incomplete checks for this condition. This can result with heap corruption and potentially remote code execution. This problem exists in all versions of Redis with Lua scripting support, starting from 2.6. The problem is fixed in versions 6.2.6, 6.0.16 and 5.0.14. For users unable to update an additional workaround to mitigate the problem without patching the redis-server executable is to prevent users from executing Lua scripts. This can be done using ACL to restrict EVAL and EVALSHA commands.","aliases":["BIT-keydb-2021-32626","BIT-redis-2021-32626","BIT-valkey-2021-32626","GHSA-p486-xggp-782c"],"modified":"2026-08-18T13:49:57.798041Z","published":"2021-10-04T18:15:08.140Z","related":["ALSA-2021:3918","ALSA-2021:3945","SUSE-SU-2021:3772-1","openSUSE-SU-2021:3772-1","openSUSE-SU-2024:11563-1"],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"10.0"},{"last_affected":"10.0"},{"introduced":"11.0"},{"last_affected":"11.0"}],"source":"CPE_STRING","vendor_product":"debian:debian_linux"},{"source":"CPE_STRING","vendor_product":"fedoraproject:fedora","cpes":["cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"33"},{"last_affected":"33"},{"introduced":"34"},{"last_affected":"34"},{"introduced":"35"},{"last_affected":"35"}]},{"cpes":["cpe:2.3:a:oracle:communications_operations_monitor:4.3:*:*:*:*:*:*:*","cpe:2.3:a:oracle:communications_operations_monitor:4.4:*:*:*:*:*:*:*","cpe:2.3:a:oracle:communications_operations_monitor:5.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"4.3"},{"last_affected":"4.3"},{"introduced":"4.4"},{"last_affected":"4.4"},{"introduced":"5.0"},{"last_affected":"5.0"}],"source":"CPE_STRING","vendor_product":"oracle:communications_operations_monitor"}]},"references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/r75490c61c2cb7b6ae2c81238fd52ae13636c60435abcd732d41531a0%40%3Ccommits.druid.apache.org%3E"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HTYQ5ZF37HNGTZWVNJD3VXP7I6MEEF42/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VL5KXFN3ATM7IIM7Q4O4PWTSRGZ5744Z/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WR5WKJWXD4D6S3DJCZ56V74ESLTDQRAB/"},{"type":"ADVISORY","url":"https://github.com/redis/redis/security/advisories/GHSA-p486-xggp-782c"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202209-17"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20211104-0003/"},{"type":"ADVISORY","url":"https://www.debian.org/security/2021/dsa-5001"},{"type":"FIX","url":"https://github.com/redis/redis/commit/666ed7facf4524bf6d19b11b20faa2cf93fdf591"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuapr2022.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/redis/redis","events":[{"introduced":"5eec376c2f56dbf617cc8bc19476fd5431cd664d"},{"fixed":"704ba5f5b22ae1ecafbcfb7a3258311c27ff94ff"},{"introduced":"17dfd7cabbf7954f92b7a1243d4bb27fee5d4500"},{"fixed":"5895d119b1c2825ff0394f30e246e036c3972bc5"},{"introduced":"445aa844b946a8f1bc21ac8554b44adb1ecb4018"},{"fixed":"4930d19e70c391750479951022e207e19111eb55"},{"fixed":"666ed7facf4524bf6d19b11b20faa2cf93fdf591"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:redis:redis:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.6"},{"fixed":"5.0.14"},{"introduced":"6.0.0"},{"fixed":"6.0.16"},{"introduced":"6.2.0"},{"fixed":"6.2.6"}]}}],"versions":["6.2.5","6.0.15","6.0.14","6.2.4","6.2.3","6.0.13","6.2.2","6.0.12","6.2.1","6.2.0","6.0.11","6.0.10","6.0.9","6.0.8","6.0.7","6.0.6","6.0.5","6.0.4","6.0.3","6.0.2","6.0.1","6.0.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-32626.json","vanir_signatures_modified":"2026-08-18T13:49:57Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"133471130975851938283878788364891376898","length":863},"id":"CVE-2021-32626-093b868b","signature_type":"Function","signature_version":"v1","source":"https://github.com/redis/redis/commit/666ed7facf4524bf6d19b11b20faa2cf93fdf591","target":{"file":"src/scripting.c","function":"redisProtocolToLuaType_Aggregate"}},{"signature_version":"v1","source":"https://github.com/redis/redis/commit/666ed7facf4524bf6d19b11b20faa2cf93fdf591","target":{"file":"src/scripting.c"},"deprecated":false,"digest":{"line_hashes":["225837462722455056665973575322483484564","332908368104229764027246929320768567349","152776945611722238572901407709898753838","231480258362443571104530391351668937168","152080370687665431621498291127945022182","270740102386829503022426859466281342572","303153827806831169292224529846645274545","111096043701500063345173966689129171899","39240831861994024281922214699553808970","330576521664161525037836581328295755166","210400014251288815407293396960932897067","31711018281809647491546303661330920486","27809397099589564893711104080372011224","300570996866144592240027126609497643737","23550491109422937495687699410202655599","266990753237110601284265085322002239266","30842747934058892533011444427297585712","238725859220939564723884504129625935467","232925004472148321596428057799505273350","95153295205331336103429842831060433078","2434405222589226196843580275261345084","5606702997388659880226569347691655561","51070930043237854372639175997016953215","146095602914262560114489503248955746643","326384158911161488728797923221966740745","199417308474835970051138777521342048511","257737864698129123593191746325375276470","122974677492190725212865591708036728339","6902884647233111978342316538775061291","52281844437206714142186794519372494664"],"threshold":0.9},"id":"CVE-2021-32626-2fa1f762","signature_type":"Line"},{"source":"https://github.com/redis/redis/commit/666ed7facf4524bf6d19b11b20faa2cf93fdf591","target":{"file":"src/scripting.c","function":"redisProtocolToLuaType"},"deprecated":false,"digest":{"function_hash":"43734288659794077213806939880441679106","length":686},"id":"CVE-2021-32626-5ff0e58f","signature_type":"Function","signature_version":"v1"},{"id":"CVE-2021-32626-bf809c62","signature_type":"Function","signature_version":"v1","source":"https://github.com/redis/redis/commit/666ed7facf4524bf6d19b11b20faa2cf93fdf591","target":{"file":"src/scripting.c","function":"ldbRedis"},"deprecated":false,"digest":{"function_hash":"289367307775234806490099118334869407297","length":489}},{"deprecated":false,"digest":{"function_hash":"187428791625482201220890903900588121737","length":2672},"id":"CVE-2021-32626-de30d6f0","signature_type":"Function","signature_version":"v1","source":"https://github.com/redis/redis/commit/666ed7facf4524bf6d19b11b20faa2cf93fdf591","target":{"file":"src/scripting.c","function":"luaReplyToRedisReply"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}