Package "valkey-server"
| Name: |
valkey-server
|
Description: |
Persistent key-value database with network interface
|
| Latest version: |
9.0.4-0ubuntu0.2 |
| Release: |
resolute (26.04) |
| Level: |
security |
| Repository: |
main |
| Head package: |
valkey |
| Homepage: |
https://valkey.io |
Links
Download "valkey-server"
Other versions of "valkey-server" in Resolute
Changelog
|
valkey (9.0.4-0ubuntu0.2) resolute-security; urgency=medium
* SECURITY UPDATE: use after free
- debian/patches/CVE-2026-56684.patch: Fix use-after-free in
tlsProcessPendingData() on CLIENT KILL (#4234) in src/tls.c.
- debian/patches/CVE-2026-63639.patch: fix: Reject corrupt stream RDB with
shared NACK across consumers (#4073) in src/rdb.c, tests/unit/dump.tcl.
- CVE-2026-56684
- CVE-2026-63639
* SECURITY UPDATE: out-of-bound read
- debian/patches/CVE-2026-85522.patch: Check and reject invalid slot import
job names during RDB load (#4210) in src/cluster_migrateslots.c,
src/valkey-check-rdb.c, tests/integration/rdb-slot-import.tcl.
- CVE-2026-85522
* debian/patches/fix-tests.patch: Repair backport validation failure in
src/cluster_migrateslots.c, src/valkey-check-rdb.c.
* debian/patches/fix-valkey-check-rdb-test.patch: Fix valkey-check-rdb test
path
-- Shishir Subedi Tue, 15 Sep 2026 11:20:23 +0545
|
| CVE-2026-56684 |
Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's tlsProcessPendingData function iterates pendin |
| CVE-2026-63639 |
Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed RDB stream |
| CVE-2026-85522 |
A vulnerability was detected in valkey-io valkey up to 9.5.4/9.1.0. Affected by this vulnerability is the function createSlotImportJob of the file sr |
|
About
-
Send Feedback to @ubuntu_updates