Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed RDB stream payload that assigns one Pending Entry List NACK to multiple consumers during stream consumer-group deserialization, causing a use-after-free when one consumer is deleted while another still references the shared NACK and potentially allowing remote code execution. This issue is fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade valkey-develUpgrade valkey-debugsourceUpgrade valkey-debuginfoUpgrade valkey | Aug 19, 2026 | Aug 18, 2026 |
| Redhat_linux | — | Upgrade valkey-debuginfoUpgrade valkeyUpgrade valkey-develUpgrade valkey-debugsource | Aug 26, 2026 | Aug 18, 2026 |
| Rocky_linux | — | Upgrade valkeyUpgrade valkey-debugsourceUpgrade valkey-develUpgrade valkey-debuginfo | Sep 15, 2026 | Sep 9, 2026 |
| Ubuntu | — | Upgrade valkey-tools (Ubuntu Pro)Upgrade valkey-tools | Sep 17, 2026 | Sep 16, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub