CVE-2018-11218: Debian Linux
Critical severity, CVSS 9.8. EPSS: 59% chance of exploitation in the next 30 days.
Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 because of stack-based buffer overflows.
Affected products
- Debian Debian Linux: version 9.0 only
- Oracle Communications Operations Monitor: version 3.4 only; version 4.0 only
- Red Hat Openstack: version 10 only; version 13 only
- Redislabs Redis: before 3.2.12 (fixed in 3.2.12); from 4.0, before 4.0.10 (fixed in 4.0.10); version 5.0 only
Published 2018-06-17. Last modified 2026-06-17.