Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <69e13713.170a0220.289f9f.6db1@mx.google.com>
Date: Thu, 16 Apr 2026 12:22:59 -0700 (PDT)
From: yangjincheng1998@...il.com
To: oss-security@...ts.openwall.com
Cc: alan.coopersmith@...cle.com
Subject: Re: Apache Kvrocks affected by CVE-2024-31449 and
 CVE-2025-49844 (Redis Lua); fixed but no formal advisory

Hi Alan,

Good catch -- sorry for the confusion. The "Duplicate - please ignore"
titles on #3433 and #3434 are my own housekeeping rename, done on
2026-04-11, AFTER the Kvrocks maintainers had already closed both
issues on 2026-04-09 via a single fix PR. The original bodies were
the actual vulnerability reports.

The authoritative, non-renamed evidence on the Kvrocks side is:

  https://github.com/apache/kvrocks/pull/3435
  Title: "fix(script): upgrade Lua version to fix CVE-2024-31449
         and CVE-2025-49844"
  Author: jihuayu (Kvrocks committer)
  Merged: 2026-04-09 03:57 UTC
  Auto-closed #3433 and #3434.

So the Kvrocks project itself, in its own fix PR title, names both
CVEs as applicable to apache/kvrocks. The downstream impact is not
in doubt -- what remains pending is a formal ASF advisory / GHSA /
Kvrocks-specific CVE ID, which was the original subject of my post.

Off-list update: ASF Security has since confirmed they plan to
coordinate with Kvrocks to publish CVEs for these issues.

Best,
Jincheng Yang
Xidian University

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.