This bug was fixed in the package valkey - 9.1.2-0ubuntu1
---------------
valkey (9.1.2-0ubuntu1) stonking; urgency=medium
* New upstream version 9.1.2 (LP: #2153491).
- Security fixes:
+ GHSA-jcj7-v34w-v9vv: Use-after-free in RDMA connection handling could
allow an authenticated client to crash the server using CLIENT KILL.
+ GHSA-fq2f-crmw-q97r: Unauthenticated use-after-free of the Lua
interpreter state via the script debugger command table.
- Bug fixes:
+ Fix double-free when a module timer callback stops its own timer.
+ Fix torn RESP3 push frames when publishing to a subscribed channel.
+ Always deep-validate listpacks on RDB load and RESTORE.
+ Fix crashes, hangs, and CPU spinning with RDMA and IO threads.
+ RESET now clears the CLIENT IMPORT-SOURCE flag.
+ Truncate partially written MULTI blocks from the AOF on short read.
+ Fix ACL bypass via duplicate STORE options in GEORADIUS.
+ Fix command log redaction leaking between MULTI commands and scripts.
+ Fix use-after-free when receiving a cluster message type from an
unloaded module.
+ Fix out-of-bounds access for cluster module message type 255.
+ AOF loading no longer performs ACL checks on replayed commands.
+ Fix mem_clients_normal leak on replicas after primary disconnects.
+ Fix client hang when a blocking command is pipelined with a partial
next command.
+ HGETEX now requires write permission on the key.
+ Compare the full TLS certificate CN during authentication.
+ Fix atomic slot migration with IO threads and TLS.
+ Reject invalid slot import ranges and job name lengths in RDB files.
+ MOVE and COPY now check ACL access to the current database.
+ Fix crash on COPY with a trailing DB option during slot migration.
+ Fix server panic when pipelined invalid-arity commands reach the key
prefetcher with IO threads.
+ HPERSIST, HTTL, HPTTL, HEXPIRETIME, and HPEXPIRETIME now return a
syntax error when the FIELDS keyword is missing.
+ Fix signed overflow crash with large hash field expiration times.
+ Fix frozen monotonic clock on hosts with unsynchronized TSC.
+ Fix stack overflow when retrying a failed TLS write of large replies.
+ Fix --check-system clocksource check on hosts using a hardware clock.
+ Fix IO threads assertion when a blocked client's pending command is
reprocessed before unblocking.
+ Sentinel no longer loads the Lua scripting engine at startup.
+ Validate cluster bus packet payload lengths to prevent remote crashes.
+ Harden stream validation on RDB load and RESTORE.
+ Reject stream payloads with mismatched live/deleted entry counts.
+ Restore IO threads throughput on socket and TLS connections.
+ Fix use-after-free when serving clients blocked on the same key.
+ Fix CLUSTER SLOT-STATS ORDERBY ordering past 2^31 counter diffs.
* Drop d/p/0006-support-openssl4-tls-tests.patch - fixed upstream.
-- Lena Voytek <[email protected]> Tue, 01 Sep 2026 16:47:57
-0400
** Changed in: valkey (Ubuntu Stonking)
Status: In Progress => Fix Released
** CVE added: https://github.com/advisories/GHSA-fq2f-crmw-q97r
** CVE added: https://github.com/advisories/GHSA-jcj7-v34w-v9vv
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2153491
Title:
Update Valkey to 7.2.14 in noble, 9.0.6 in resolute, and 9.1.2 in
stonking
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/valkey/+bug/2153491/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs