A memory corruption bug that's been in the Redis source code for around 13 years is to blame for the vulnerability. An authenticated attacker could exploit it with a script written in the Lua language ...