CVE-2020-14147: Debian Linux

High severity, CVSS 7.7. EPSS: 3.1% chance of exploitation in the next 30 days.

An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and application crash) or possibly bypass intended sandbox restrictions via a large number, which triggers a stack-based buffer overflow. NOTE: this issue exists because of a CVE-2015-8080 regression.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Oracle Communications Operations Monitor: version 3.4 only; version 4.1 only; version 4.2 only; version 4.3 only
  • Redislabs Redis: before 5.0.9 (fixed in 5.0.9); from 6.0.0, before 6.0.3 (fixed in 6.0.3)
  • Suse Linux Enterprise: version 12.0 only

Published 2020-06-15. Last modified 2026-06-17.