UbuntuUpdates.org

Package "valkey"

Name: valkey

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • Conversion script and compatibility symlinks for Redis
  • Persistent key-value database with network interface (monitoring)
  • Persistent key-value database with network interface
  • Persistent key-value database with network interface (client)

Latest version: 8.0.6+dfsg1-0ubuntu0.1
Release: plucky (25.04)
Level: proposed
Repository: universe

Links



Other versions of "valkey" in Plucky

Repository Area Version
base universe 8.0.2+dfsg1-1ubuntu1
updates universe 8.0.4+dfsg1-0ubuntu0.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: *DELETED* 2025-10-23 05:07:12 UTC
No changelog for deleted or moved packages.

Version: 8.0.6+dfsg1-0ubuntu0.1 2025-10-23 03:07:25 UTC

  valkey (8.0.6+dfsg1-0ubuntu0.1) plucky; urgency=medium

  * New upstream version 8.0.6 (LP: #2127122)
    - Security fixes:
      + CVE-2025-49844: Lua script may lead to remote code execution.
      + CVE-2025-46817: Lua script may lead to int overflow and potential RCE.
      + CVE-2025-46818: Lua script can be executed in context of another user.
      + CVE-2025-46819: LUA out-of-bound read.
      + CVE-2025-49112: Integer underflow in setDeferredReply networking.c.
      + CVE-2025-27151: Check length of AOF file name in valkey-check-aof and
        reject paths longer than PATH_MAX.
    - Bug fixes:
      + Fix accounting for dual channel RDB bytes in replication stats.
      + Fix dual rdb channel connection conn error log.
      + Only mark the client reprocessing flag when unblocked on keys.
      + Fix memory corruption in sharded pubsub unsubscribe.
      + Free module context even if there was no content written in auxsave2.
      + Do not unpause paused clients with client unblock.
      + Fix Detect SSL_new() returning NULL in outgoing connections.
      + Correctly cast the extension lengths.
      + Fix replica can't finish failover when config epoch is outdated.
      + Fix cluster wrong myself port after updating port/tls-port.
      + Ensure empty error tables in scripts don't crash Valkey.
      + Fix client tracking memory overhead calculation.
      + Converge shard-id persisted in nodes.conf to primary's shard id.
      + Fix pre-size hashtables per slot when reading RDB files.
    - Updates:
      + Trigger the election as soon as possible when doing a forced manual
        failover.
      + Make manual failover reset the on-going election to promote failover.
      + Fix logs when failover auth denied due to slot epoch.
    - Features:
      + Add a filter option to drop all cluster packets.

 -- Lena Voytek <email address hidden> Sat, 11 Oct 2025 23:25:21 -0400

2127122 Update Valkey to 7.2.11 in noble, 8.0.6 in plucky, and 8.1.4 in questing + resolute
CVE-2025-49844 Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lu
CVE-2025-46817 Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lu
CVE-2025-46818 Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lu
CVE-2025-46819 Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted LU
CVE-2025-49112 setDeferredReply in networking.c in Valkey through 8.1.1 has an integer underflow for prev->size - prev->used.
CVE-2025-27151 Redis is an open source, in-memory database that persists on disk. In versions starting from 7.0.0 to before 8.0.2, a stack-based buffer overflow exi

Version: *DELETED* 2025-09-01 22:21:05 UTC
No changelog for deleted or moved packages.

Version: 8.0.4+dfsg1-0ubuntu0.1 2025-08-23 03:07:13 UTC

  valkey (8.0.4+dfsg1-0ubuntu0.1) plucky; urgency=medium

  * New upstream version 8.0.4 (LP: #2115258)
    - Security fixes:
      + CVE-2025-21605: Allocation of Resources Without Limits or Throttling.
      + CVE-2025-32023: Out-of-bounds write during hyperloglog operations
      + CVE-2025-48367: IP Protocol errors resulting in DoS
    - Bug fixes:
      + Optimize RDB Load Performance and Fix Cluster Mode Resizing.
      + Fix memory leak in forgotten node ping ext code path.
      + Fix cluster info sent stats for message with light header.
      + Fix module LatencyAddSample still work when latency-monitor-threshold
        is 0.
      + Fix raxRemove crash at memcpy() due to key size exceeds max Rax size.
      + Fix error "SSL routines::bad length" when connTLSWrite is called
        second time with smaller buffer.
      + Fix temp file leak druing replication error handling.
      + Fix ACL LOAD crash on replica since the primary client don't has a
        user.
      + Fix RANDOMKEY infinite loop during CLIENT PAUSE.
      + Fix adding samples to stream object consumer trees.
      + Fix cluster slot stats assertion during promotion of replica.
      + Fix panic in primary when blocking shutdown after previous block with
        timeout.
      + Ignore stale gossip packets that arrive out of order.
      + Fix incorrect lag reported in XINFO GROUPS.
      + Avoid shard id update of replica if not matching with primary shard id.

 -- Lena Voytek <email address hidden> Tue, 24 Jun 2025 14:45:07 -0400

2115258 Update Valkey to 7.2.10 in noble, 8.0.4 in plucky, and 8.1.3 in questing
CVE-2025-21605 Redis is an open source, in-memory database that persists on disk. In versions starting at 2.6 and prior to 7.4.3, An unauthenticated client can caus
CVE-2025-32023 Redis is an open source, in-memory database that persists on disk. From 2.8 to before 8.0.3, 7.4.5, 7.2.10, and 6.2.19, an authenticated user may use
CVE-2025-48367 Redis is an open source, in-memory database that persists on disk. An unauthenticated connection can cause repeated IP protocol errors, leading to cl

Version: *DELETED* 2025-07-08 03:07:17 UTC
No changelog for deleted or moved packages.



About   -   Send Feedback to @ubuntu_updates