|
|
Message-ID: <69e13713.170a0220.289f9f.6db1@mx.google.com>
Date: Thu, 16 Apr 2026 12:22:59 -0700 (PDT)
From: yangjincheng1998@...il.com
To: oss-security@...ts.openwall.com
Cc: alan.coopersmith@...cle.com
Subject: Re: Apache Kvrocks affected by CVE-2024-31449 and
CVE-2025-49844 (Redis Lua); fixed but no formal advisory
Hi Alan,
Good catch -- sorry for the confusion. The "Duplicate - please ignore"
titles on #3433 and #3434 are my own housekeeping rename, done on
2026-04-11, AFTER the Kvrocks maintainers had already closed both
issues on 2026-04-09 via a single fix PR. The original bodies were
the actual vulnerability reports.
The authoritative, non-renamed evidence on the Kvrocks side is:
https://github.com/apache/kvrocks/pull/3435
Title: "fix(script): upgrade Lua version to fix CVE-2024-31449
and CVE-2025-49844"
Author: jihuayu (Kvrocks committer)
Merged: 2026-04-09 03:57 UTC
Auto-closed #3433 and #3434.
So the Kvrocks project itself, in its own fix PR title, names both
CVEs as applicable to apache/kvrocks. The downstream impact is not
in doubt -- what remains pending is a formal ASF advisory / GHSA /
Kvrocks-specific CVE ID, which was the original subject of my post.
Off-list update: ASF Security has since confirmed they plan to
coordinate with Kvrocks to publish CVEs for these issues.
Best,
Jincheng Yang
Xidian University
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.