Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's tlsProcessPendingData function iterates pending_list while an authenticated client can trigger CLIENT KILL, causing connTLSClose to delete the iterator's cached next node and producing a use-after-free that can crash the server or potentially allow remote code execution when TLS is enabled. This issue is fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade valkey-develUpgrade valkey-debuginfoUpgrade valkey-debugsourceUpgrade valkey | Aug 19, 2026 | Aug 18, 2026 |
| Redhat_linux | — | Upgrade valkey-debuginfoUpgrade valkey-develUpgrade valkey-debugsourceUpgrade valkey | Aug 26, 2026 | Aug 18, 2026 |
| Rocky_linux | — | Upgrade valkey-develUpgrade valkey-debugsourceUpgrade valkey-debuginfoUpgrade valkey | Sep 15, 2026 | Sep 9, 2026 |
| Ubuntu | — | Upgrade valkey-tools (Ubuntu Pro)Upgrade valkey-tools | Sep 17, 2026 | Sep 16, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub