Source: valkey Version: 9.1.1-1 Severity: important Tags: security upstream Forwarded: https://github.com/valkey-io/valkey/issues/4222 X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for valkey. CVE-2026-86227[0]: | A weakness has been identified in valkey-io valkey up to | 9.0.5/9.1.1. This affects the function kvstoreGetHashtable of the | file src/kvstore.c. This manipulation of the argument didx causes | out-of-bounds read. It is possible to initiate the attack remotely. | The attack is considered to have high complexity. It is indicated | that the exploitability is difficult. The exploit has been made | available to the public and could be used for attacks. Patch name: | 4691888e7fab3df128f0bde5750c9fde2ae552fa. To fix this issue, it is | recommended to deploy a patch. Exploitation requires cluster mode | plus attacker-controlled dump.rdb at startup (data-dir write access, | replication feed, or a stored crafted RDB) - an attacker-position | DoS at boot, not network pre-auth. The issue report was closed | stating it "is worth fixing for the sake of memory safety… but I | don't think it meets our bar for a security disclosure." If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-86227 https://www.cve.org/CVERecord?id=CVE-2026-86227 [1] https://github.com/valkey-io/valkey/issues/4222 [2] https://github.com/valkey-io/valkey/pull/4229 [3] https://github.com/valkey-io/valkey/commit/015c4d84682a6b214f1c8e6d502668cb51653860 Please adjust the affected versions in the BTS as needed. Regards, Salvatore

