vulns.co
/
GKData.io MCP

MEMemory safety and parser contracts · 2 min read

Redis Lua object lifetime failure crossed the scripting boundary

ZDI awarded Wiz researchers USD 40,000 for this single Pwn2Own Berlin 2025 entry.

Read the primary source MEMemory safety and parser contractsReviewed 2026-10-02

Root cause

Lua garbage collection could leave an object referenced after its memory was freed, undermining the interpreter’s memory-safety assumptions.

Demonstrated impact

The vendor confirms possible native code execution by an authenticated user able to run Lua scripts. This crosses the scripting boundary; host impact remains dependent on process privileges and deployment isolation.

Lessons for review

  • Review object-lifetime invariants across embedded interpreters and native components.
  • Grant scripting access only where needed and retain least-privilege service execution.
  • Check corrected vendor release guidance instead of relying on an early fixed-version summary.

Award and evidence

USD 40,000Competition Award · Organizer Confirmed

One competition-entry award, not the researchers’ event total. Official rules specify US currency; recipient allocation and actual cash settlement are unverified.

Read the researcher’s explicit CVE-to-Pwn2Own submission timeline and matched its date, product and named researchers to the organizer’s individual-entry award; corroborated CVE and scope with vendor guidance. Official rules establish USD denomination.

  • Single competition-entry award; individual recipient splits and cash-transfer date are unknown.
  • The October 6 article is the primary research publication; May demonstration and October 3 vendor advisory are distinct events.
  • Vendor Redis Software release labels were corrected on October 27 and October 30, 2025; this record does not assume every product variant was fixed in its originally listed version.

Recorded timeline

Published
2025-10-06explicit · Primary research article publication; earlier competition results are separately dated.
Public Disclosure
2025-05-16explicit · Public demonstration and result; vendor technical advisory followed later.
Reported
2025-05-16explicit · Researcher timeline explicitly ties this CVE to its May 16 Pwn2Own report.
Awarded
2025-05-16explicit · Award announced for the named individual entry.
Fixed
2025-10-03explicit · Researcher article states that Redis released its advisory and patched version on this date. This is not a universal customer-deployment date; later vendor corrections affected some Redis Software fixed-version labels.
Award Announced
2025-05-16explicit

Related visual models

Sources and provenance

  1. RediShell: Redis CVE-2025-49844 Benny Isaacs and Nir Brakha / Wiz Research · reviewed 2026-10-02
  2. Pwn2Own Berlin 2025 daily results Dustin Childs / Zero Day Initiative · reviewed 2026-10-02
  3. Pwn2Own Berlin 2025 rules Trend Micro Zero Day Initiative · reviewed 2026-10-02
  4. Redis Lua Use-After-Free security advisory Redis maintainers · reviewed 2026-10-02
  5. Redis CVE-2025-49844 remediation guidance and corrections Riaz Lakhani / Redis · reviewed 2026-10-02

Record reviewed 2026-10-02. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software