|
|
Log in / Subscribe / Register

Ubuntu alert USN-7893-1 (valkey)

From:  noreply+usn-bot@canonical.com
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-7893-1] Valkey vulnerabilities
Date:  Wed, 26 Nov 2025 14:26:22 +0000
Message-ID:  <E1vOGTO-0004CA-ET@lists.ubuntu.com>

========================================================================== Ubuntu Security Notice USN-7893-1 November 26, 2025 valkey vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 25.04 - Ubuntu 24.04 LTS Summary: Several security issues were fixed in Valkey. Software Description: - valkey: Persistent key-value database with network interface Details: Benny Isaacs, Nir Brakha, and Sagi Tzadik discovered that Valkey incorrectly handled memory when running Lua scripts. An authenticated attacker could use this vulnerability to trigger a use-after-free condition, and potentially achieve remote code execution on the Valkey server. (CVE-2025-49844) It was discovered that Valkey incorrectly handled memory when running Lua scripts. An authenticated attacker could use this vulnerability to trigger a integer overflow condition, and potentially achieve remote code execution on the Valkey server. (CVE-2025-46817) It was discovered that Valkey incorrectly handled Lua objects. An authenticated attacker could possibly use this issue to escalate their privileges. (CVE-2025-46818) It was discovered that Valkey incorrectly handled memory when running Lua scripts. An authenticated attacker could use this vulnerability to read out-of-bounds memory, causing a denial of service or possibly obtaining sensitive information. (CVE-2025-46819) It was discovered that Valkey incorrectly handled memory in some calculations. An attacker could possibly use this issue to cause a denial of service. (CVE-2025-49112) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 valkey-server 8.1.4+dfsg1-0ubuntu0.2 Ubuntu 25.04 valkey-server 8.0.6+dfsg1-0ubuntu0.2 Ubuntu 24.04 LTS valkey-server 7.2.11+dfsg1-0ubuntu0.2 This update uses a new upstream release, which includes additional bug fixes. In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7893-1 CVE-2025-46817, CVE-2025-46818, CVE-2025-46819, CVE-2025-49112, CVE-2025-49844 Package Information: https://launchpad.net/ubuntu/+source/valkey/8.1.4+dfsg1-0... https://launchpad.net/ubuntu/+source/valkey/8.0.6+dfsg1-0... https://launchpad.net/ubuntu/+source/valkey/7.2.11+dfsg1-...


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmknDRIACgkQcpJm3tlz hgFkJxAAlAtvCTFo3R1/VdddYITCJu742ZwudYjIFI9UXCLZ1MJN3XQbHGOgLK6b FCI76f1/4ksmo99QyteIbPtormE4FkSeJ/RkkpgQlFFCkUdVELFatibh/qxgE57y mJ7y7ipnqtIohz9oQTH0hFApKofPEx7qzMkDF6SxKvkZyu6peAyxd+2ER/KJl/YJ W8U1y4aa1vnCjSSec7R2d4eypOTbylR6fFu/6Sz0GmetIIEoUSfy4t7AUf67hqlR uSl821nq3/LZfc9fvwdm8BGAgcMMgKOeK0RoWPUlMGK6RDPLdJS2GcszH1ATIFSd aMkxMssVHriPrDIQayDVroN+RM4LDOcanFOwQNzXksihj6njzazmBWxcU2t3+FNA PvZ+9fG5KELrzWSizBwDeHZpxWot/277IQnA06vZP4r2RSEvYlUFOCgGVhCilSag uPlpsW9BVd7L5MTiWpqlYHrQVTV5RyxddEF40x8lJDRh/zRXa7pMPHEFV4ars1af T/qASS6LtBBoz20/wLtbwLVcmhD0AWR9kReDYuMd7KWje6sSZArPMhZYeRkLKOQc YpigwoT4ikG6hc2l3ghcna9Va9fR8zWcRbQ4dMUuYlbwZtREHw6krStBnqYnlkjW OLQ7pczQnVFaHXovDGqz2SN4I6fb8VpyRjug2XZifTysxzPj7mY= =qKAv -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds