Skip to content

Heap overflow issue (CVE-2022-24834) #92

@l2dy

Description

@l2dy

Redis patched their vendored version of lua-cjson in Jul 2023 to fix a heap overflow issue and CVE-2022-24834 was assigned. It seems that those changes were never upstreamed.

We may want to merge the changes, like what OpenResty's fork did in openresty#94.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions