This bug was fixed in the package valkey - 8.0.6+dfsg1-0ubuntu0.1
---------------
valkey (8.0.6+dfsg1-0ubuntu0.1) plucky; urgency=medium
* New upstream version 8.0.6 (LP: #2127122)
- Security fixes:
+ CVE-2025-49844: Lua script may lead to remote code execution.
+ CVE-2025-46817: Lua script may lead to int overflow and potential RCE.
+ CVE-2025-46818: Lua script can be executed in context of another user.
+ CVE-2025-46819: LUA out-of-bound read.
+ CVE-2025-49112: Integer underflow in setDeferredReply networking.c.
+ CVE-2025-27151: Check length of AOF file name in valkey-check-aof and
reject paths longer than PATH_MAX.
- Bug fixes:
+ Fix accounting for dual channel RDB bytes in replication stats.
+ Fix dual rdb channel connection conn error log.
+ Only mark the client reprocessing flag when unblocked on keys.
+ Fix memory corruption in sharded pubsub unsubscribe.
+ Free module context even if there was no content written in auxsave2.
+ Do not unpause paused clients with client unblock.
+ Fix Detect SSL_new() returning NULL in outgoing connections.
+ Correctly cast the extension lengths.
+ Fix replica can't finish failover when config epoch is outdated.
+ Fix cluster wrong myself port after updating port/tls-port.
+ Ensure empty error tables in scripts don't crash Valkey.
+ Fix client tracking memory overhead calculation.
+ Converge shard-id persisted in nodes.conf to primary's shard id.
+ Fix pre-size hashtables per slot when reading RDB files.
- Updates:
+ Trigger the election as soon as possible when doing a forced manual
failover.
+ Make manual failover reset the on-going election to promote failover.
+ Fix logs when failover auth denied due to slot epoch.
- Features:
+ Add a filter option to drop all cluster packets.
-- Lena Voytek <[email protected]> Sat, 11 Oct 2025 23:25:21
-0400
** Changed in: valkey (Ubuntu Noble)
Status: Fix Committed => Fix Released
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2127122
Title:
Update Valkey to 7.2.11 in noble, 8.0.6 in plucky, and 8.1.4 in
questing + resolute
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/valkey/+bug/2127122/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs