CVE-2024-46981 is a use-after-free vulnerability in Redis Lua scripting. An authenticated Redis user can execute a specially crafted Lua script that manipulates the Lua garbage collector, potentially resulting in remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a working exploit for CVE-2024-46981, targeting Redis 6.2.11. The exploit consists of a main Python script (exploit.py) and several supporting Lua scripts (stage1-clear-heap.lua, stage1-forge-objects.lua, stage1-leak-tstring.lua, stage1-uaf.lua) that are used to manipulate the Redis Lua scripting environment and heap. The Python script orchestrates a multi-stage attack: it uploads and executes the Lua scripts to leak memory addresses, forge objects, and trigger a use-after-free vulnerability, ultimately achieving remote code execution. The final payload is a bash reverse shell that connects from the Redis server to an attacker-controlled host and port, specified via command-line arguments. The exploit requires network access to the Redis server (default port 6379) and optionally a password. The repository is structured with clear separation between the exploit logic (Python) and the heap manipulation primitives (Lua), and is operational, providing a real reverse shell if successful.
This repository is a functional exploit for CVE-2024-46981, targeting Redis 6.2.11. The exploit is implemented in Python (exploit.py) and leverages several Lua scripts (stage1-forge-objects.lua, stage1-leak-tstring.lua, stage1-uaf.lua, stage1-clear-heap.lua) to manipulate the Redis Lua scripting environment and heap. The exploit works by connecting to a target Redis instance over the network (default port 6379), uploading and executing the Lua scripts to perform heap grooming, leak heap addresses, and trigger a use-after-free vulnerability. The final stage executes a reverse shell payload, connecting back to an attacker-controlled host and port specified via command-line arguments. The repository includes a requirements.txt for the Python Redis client. The exploit requires the attacker to have network access to the Redis instance and, if set, the password. The overall structure is modular, with the main logic in exploit.py orchestrating the stages and Lua scripts. The exploit is operational and provides a working remote code execution vector against vulnerable Redis servers.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Redis vulnerability in Lua library commands that may permit remote code execution.
A critical Redis remote-code-execution vulnerability involving Lua library commands. The referenced Rocky Linux security update addresses it, and the plugin explicitly reports exploits as available.
Unknown
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.