
Proof-of-concept exploit for Redis 8.2.1 Lua parser use-after-free, racing garbage collection via crafted loadstring calls to achieve remote code execution.
Lua chunk-name GC race leading to Redis 8.2.1 use-after-free and remote code execution.
Redis embeds Lua 5.1 for scripting. In versions up to 8.2.1 the luaY_parser function does NOT anchor the chunk name string on the Lua stack before invoking the lexer. A crafted script can trigger garbage collection while the parser still references the freed string, producing a UAF that leads to native code execution.
redis-cliCVE-2025-49844.lua – hammer the parser with thousands of loadstring calls and a GC-enabled chunk name to win the race.while redis-cli -h localhost -p 6379 --eval CVE-2025-49844.lua >/dev/null; do
printf '.'
done
Expected result:
On vulnerable builds the Redis process eventually crashes or drops the connection. Patched 8.2.2 (commit d5728cb5795c966c5b5b1e0f0ac576a7e69af539) anchors the chunk name and the script runs harmlessly.
Upgrade to Redis 8.2.2 or later, or disable Lua scripting for untrusted users.