oss-sec mailing list archives

Re: Apache Kvrocks affected by CVE-2024-31449 and CVE-2025-49844 (Redis Lua); fixed but no formal advisory


From: yangjincheng1998 () gmail com
Date: Thu, 16 Apr 2026 12:22:59 -0700 (PDT)

Hi Alan,

Good catch -- sorry for the confusion. The "Duplicate - please ignore"
titles on #3433 and #3434 are my own housekeeping rename, done on
2026-04-11, AFTER the Kvrocks maintainers had already closed both
issues on 2026-04-09 via a single fix PR. The original bodies were
the actual vulnerability reports.

The authoritative, non-renamed evidence on the Kvrocks side is:

  https://github.com/apache/kvrocks/pull/3435
  Title: "fix(script): upgrade Lua version to fix CVE-2024-31449
         and CVE-2025-49844"
  Author: jihuayu (Kvrocks committer)
  Merged: 2026-04-09 03:57 UTC
  Auto-closed #3433 and #3434.

So the Kvrocks project itself, in its own fix PR title, names both
CVEs as applicable to apache/kvrocks. The downstream impact is not
in doubt -- what remains pending is a formal ASF advisory / GHSA /
Kvrocks-specific CVE ID, which was the original subject of my post.

Off-list update: ASF Security has since confirmed they plan to
coordinate with Kvrocks to publish CVEs for these issues.

Best,
Jincheng Yang
Xidian University


Current thread: