Root cause
Lua garbage collection could leave an object referenced after its memory was freed, undermining the interpreter’s memory-safety assumptions.
Demonstrated impact
The vendor confirms possible native code execution by an authenticated user able to run Lua scripts. This crosses the scripting boundary; host impact remains dependent on process privileges and deployment isolation.
Lessons for review
- Review object-lifetime invariants across embedded interpreters and native components.
- Grant scripting access only where needed and retain least-privilege service execution.
- Check corrected vendor release guidance instead of relying on an early fixed-version summary.
Award and evidence
One competition-entry award, not the researchers’ event total. Official rules specify US currency; recipient allocation and actual cash settlement are unverified.
Read the researcher’s explicit CVE-to-Pwn2Own submission timeline and matched its date, product and named researchers to the organizer’s individual-entry award; corroborated CVE and scope with vendor guidance. Official rules establish USD denomination.
- Single competition-entry award; individual recipient splits and cash-transfer date are unknown.
- The October 6 article is the primary research publication; May demonstration and October 3 vendor advisory are distinct events.
- Vendor Redis Software release labels were corrected on October 27 and October 30, 2025; this record does not assume every product variant was fixed in its originally listed version.
Recorded timeline
- Published
- 2025-10-06explicit · Primary research article publication; earlier competition results are separately dated.
- Public Disclosure
- 2025-05-16explicit · Public demonstration and result; vendor technical advisory followed later.
- Reported
- 2025-05-16explicit · Researcher timeline explicitly ties this CVE to its May 16 Pwn2Own report.
- Awarded
- 2025-05-16explicit · Award announced for the named individual entry.
- Fixed
- 2025-10-03explicit · Researcher article states that Redis released its advisory and patched version on this date. This is not a universal customer-deployment date; later vendor corrections affected some Redis Software fixed-version labels.
- Award Announced
- 2025-05-16explicit
Sources and provenance
- RediShell: Redis CVE-2025-49844 Benny Isaacs and Nir Brakha / Wiz Research · reviewed 2026-10-02
- Pwn2Own Berlin 2025 daily results Dustin Childs / Zero Day Initiative · reviewed 2026-10-02
- Pwn2Own Berlin 2025 rules Trend Micro Zero Day Initiative · reviewed 2026-10-02
- Redis Lua Use-After-Free security advisory Redis maintainers · reviewed 2026-10-02
- Redis CVE-2025-49844 remediation guidance and corrections Riaz Lakhani / Redis · reviewed 2026-10-02
Record reviewed 2026-10-02. Snapshot d5550c789111. Open the complete JSON contract.