oss-sec mailing list archives
Re: Apache Kvrocks affected by CVE-2024-31449 and CVE-2025-49844 (Redis Lua); fixed but no formal advisory
From: yangjincheng1998 () gmail com
Date: Thu, 16 Apr 2026 12:22:59 -0700 (PDT)
Hi Alan, Good catch -- sorry for the confusion. The "Duplicate - please ignore" titles on #3433 and #3434 are my own housekeeping rename, done on 2026-04-11, AFTER the Kvrocks maintainers had already closed both issues on 2026-04-09 via a single fix PR. The original bodies were the actual vulnerability reports. The authoritative, non-renamed evidence on the Kvrocks side is: https://github.com/apache/kvrocks/pull/3435 Title: "fix(script): upgrade Lua version to fix CVE-2024-31449 and CVE-2025-49844" Author: jihuayu (Kvrocks committer) Merged: 2026-04-09 03:57 UTC Auto-closed #3433 and #3434. So the Kvrocks project itself, in its own fix PR title, names both CVEs as applicable to apache/kvrocks. The downstream impact is not in doubt -- what remains pending is a formal ASF advisory / GHSA / Kvrocks-specific CVE ID, which was the original subject of my post. Off-list update: ASF Security has since confirmed they plan to coordinate with Kvrocks to publish CVEs for these issues. Best, Jincheng Yang Xidian University
Current thread:
- Apache Kvrocks affected by CVE-2024-31449 and CVE-2025-49844 (Redis Lua); fixed but no formal advisory yangjincheng1998 (Apr 16)
- Re: Apache Kvrocks affected by CVE-2024-31449 and CVE-2025-49844 (Redis Lua); fixed but no formal advisory Alan Coopersmith (Apr 16)
- Re: Apache Kvrocks affected by CVE-2024-31449 and CVE-2025-49844 (Redis Lua); fixed but no formal advisory yangjincheng1998 (Apr 16)
- Re: Apache Kvrocks affected by CVE-2024-31449 and CVE-2025-49844 (Redis Lua); fixed but no formal advisory Alan Coopersmith (Apr 16)
