oss-sec mailing list archives
Re: Apache Kvrocks affected by CVE-2024-31449 and CVE-2025-49844 (Redis Lua); fixed but no formal advisory
From: Solar Designer <solar () openwall com>
Date: Thu, 16 Apr 2026 21:34:51 +0200
Hi, Disclaimer: I'm replying based on limited context, without looking into the actual issues. On Thu, Apr 16, 2026 at 12:22:59PM -0700, yangjincheng1998 () gmail com wrote:
Good catch -- sorry for the confusion. The "Duplicate - please ignore" titles on #3433 and #3434 are my own housekeeping rename, done on 2026-04-11, AFTER the Kvrocks maintainers had already closed both issues on 2026-04-09 via a single fix PR. The original bodies were the actual vulnerability reports.
What you did is very confusing. It looks like you created the issues on 2026-04-08, so I don't see why having them fixed a day later would make them "duplicate" or "submitted in error". Maybe it was your attempt to hide the vulnerability reports until proper publication? If so, I think that was a bad idea. I suggest that you restore your original titles and content of these issues. The original content is seen in the edits history anyway, it's just harder to find now. Thanks, Alexander
Current thread:
- Apache Kvrocks affected by CVE-2024-31449 and CVE-2025-49844 (Redis Lua); fixed but no formal advisory yangjincheng1998 (Apr 16)
- Re: Apache Kvrocks affected by CVE-2024-31449 and CVE-2025-49844 (Redis Lua); fixed but no formal advisory Alan Coopersmith (Apr 16)
- Re: Apache Kvrocks affected by CVE-2024-31449 and CVE-2025-49844 (Redis Lua); fixed but no formal advisory yangjincheng1998 (Apr 16)
- Re: Apache Kvrocks affected by CVE-2024-31449 and CVE-2025-49844 (Redis Lua); fixed but no formal advisory Solar Designer (Apr 16)
- Re: Apache Kvrocks affected by CVE-2024-31449 and CVE-2025-49844 (Redis Lua); fixed but no formal advisory yangjincheng1998 (Apr 16)
- Re: Apache Kvrocks affected by CVE-2024-31449 and CVE-2025-49844 (Redis Lua); fixed but no formal advisory yangjincheng1998 (Apr 16)
- Re: Apache Kvrocks affected by CVE-2024-31449 and CVE-2025-49844 (Redis Lua); fixed but no formal advisory Alan Coopersmith (Apr 16)
