Source: valkey Version: 9.1.1-1 Severity: important Tags: security upstream Forwarded: https://github.com/valkey-io/valkey/issues/4207 X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for valkey. CVE-2026-85522[0]: | A vulnerability was detected in valkey-io valkey up to 9.5.4/9.1.0. | Affected by this vulnerability is the function createSlotImportJob | of the file src/cluster_migrateslots.c of the component Slot | Migration. The manipulation of the argument job_name results in out- | of-bounds read. The attack can be executed remotely. The exploit is | now public and may be used. Upgrading to version 9.0.5 and 9.1.1 | addresses this issue. The patch is identified as | f4dc3ca09eb650c2fe14060090a41c524eca803f. Upgrading the affected | component is advised. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-85522 https://www.cve.org/CVERecord?id=CVE-2026-85522 [1] https://github.com/valkey-io/valkey/issues/4207 [2] https://github.com/valkey-io/valkey/pull/4210 [3] https://github.com/valkey-io/valkey/commit/8f9f19d311bbbaf916ef620a37440c96f726b2b7 Please adjust the affected versions in the BTS as needed. Regards, Salvatore

