Source: valkey
Version: 9.1.1-1
Severity: important
Tags: security upstream
Forwarded: https://github.com/valkey-io/valkey/issues/4222
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for valkey.

CVE-2026-86227[0]:
| A weakness has been identified in valkey-io valkey up to
| 9.0.5/9.1.1. This affects the function kvstoreGetHashtable of the
| file src/kvstore.c. This manipulation of the argument didx causes
| out-of-bounds read. It is possible to initiate the attack remotely.
| The attack is considered to have high complexity. It is indicated
| that the exploitability is difficult. The exploit has been made
| available to the public and could be used for attacks. Patch name:
| 4691888e7fab3df128f0bde5750c9fde2ae552fa. To fix this issue, it is
| recommended to deploy a patch. Exploitation requires cluster mode
| plus attacker-controlled dump.rdb at startup (data-dir write access,
| replication feed, or a stored crafted RDB) - an attacker-position
| DoS at boot, not network pre-auth. The issue report was closed
| stating it "is worth fixing for the sake of memory safety… but I
| don't think it meets our bar for a security disclosure."


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-86227
    https://www.cve.org/CVERecord?id=CVE-2026-86227
[1] https://github.com/valkey-io/valkey/issues/4222
[2] https://github.com/valkey-io/valkey/pull/4229
[3] 
https://github.com/valkey-io/valkey/commit/015c4d84682a6b214f1c8e6d502668cb51653860

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to