CVE-2022-0543Exploit(canonical / debian_linux)

MEDIUMCVSS 10.0 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch canonical debian_linux systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.

4.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-04-18. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-862

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • redis
  • ubuntu_linux

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-18); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
debian_linuxredisubuntu_linux

6 versions affected across 3 products

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-18: 1Mentions · 2026-05-21: 1Mentions · 2026-05-22: 1Active Exploitation · 2026-05-21: 1Patch / Workaround · 2026-03-18: 1Technical Details · 2026-03-18: 103-1805-2105-22
Signal classification3 categories
Exploit
133.3%
Active Exploitation
133.3%
General
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-181
Exploit1
2026-05-211
Active Exploitation1
2026-05-221
General1
Full discourse3 posts
  • The Daily Tech Feed@dailytechonx
    General

    P2PInfect botnet targets Kubernetes clusters via exposed Redis instances, exploiting CVE-2022-0543. Secure your cloud environments now! #CyberSecurity #Kubernetes #Redis #P2PInfect #CloudSecurity Link: https://thedailytechfeed.com/p2pinfect-botnet-targets-kubernetes-via-exposed-redis-exploits-critical-cve-2022-0543-vulnerability/ https://t.co/2DhmYBdqtF

    Post summary

    The post highlights a botnet targeting Kubernetes via exposed Redis using CVE‑2022‑0543, but provides no detailed exploitation, patching, or technical specifics.

    0100048
    345 followersView on X
  • ThreadLinqs@threadlinqs
    Active Exploitation

    NEW THREAT INTEL: P2Pinfect botnet in GKE via exposed Redis - 6mo dormant, CVE-2022-0543. 9 detections, 31 IOCs. https://intel.threadlinqs.com/#TL-2026-0537 #ThreatIntel #Kubernetes #Redis https://t.co/l7Se99QYgY

    Post summary

    Threat intel report lists the P2Pinfect botnet exploiting CVE-2022-0543 via exposed Redis in GKE, with nine detections and 31 IOCs indicating ongoing attacks.

    0000046
    51 followersView on X
  • FirstPassLab@FirstPassLab
    Exploit

    Tenzai's AI hacker solved a Dreamhack difficulty 8/10 CTF challenge by autonomously chaining 3 attacks: 1️⃣ SSRF via /api/http with IP check bypass 2️⃣ Prototype pollution in class-transformer to escalate to admin 3️⃣ Redis RCE via CVE-2022-0543 Total cost: $12.92. Total time: ~2 hours. The agent tracked leads, managed state across attack paths, and coordinated sub-agents — behaviors that used to require an experienced pentester with years of CTF practice. Your static ACLs and signature-based IPS can't detect this. Each individual step passes inspection. The power is in the combination. Defensive answer: TrustSec SGT microsegmentation at Layer 2/3. Every lateral movement attempt hits an identity-based policy check. Multiply attack complexity exponentially. show cts role-based permissions — if you can't run this on your access switches, you're behind. #CCIE #CCIESecurity #ZeroTrust #AIHacking #NetworkSecurity #Cybersecurity

    Post summary

    The post illustrates an AI‑driven chain of exploits (SSRF, prototype pollution, Redis RCE CVE‑2022‑0543) that bypass conventional defenses, highlighting microsegmentation as a recommended mitigation.

    0000055
    10 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
OScanonicalubuntu_linux20.04--
OScanonicalubuntu_linux21.10--
OSdebiandebian_linux10.0--
OSdebiandebian_linux11.0--
OSdebiandebian_linux9.0--
Appredisredis---

Explore more