Package "valkey"
WARNING: the "valkey" package was deleted from this repository
| Name: |
valkey
|
Description: |
This package is just an umbrella for a group of other packages,
it has no description. Description samples from packages in group:
- Persistent key-value database with network interface (monitoring)
- Persistent key-value database with network interface
- Persistent key-value database with network interface (client)
|
| Latest version: |
*DELETED* |
| Release: |
questing (25.10) |
| Level: |
proposed |
| Repository: |
universe |
Links
Other versions of "valkey" in Questing
Packages in group
Deleted packages are displayed in grey.
Changelog
|
valkey (8.1.7+dfsg1-0ubuntu0.1) questing; urgency=medium
* New upstream version 8.1.7 (LP: #2151296)
- Security fixes:
+ CVE-2026-23479: Use-After-Free in unblock client flow.
+ CVE-2026-25243: Invalid Memory Access in RESTORE command.
+ CVE-2026-23631: Use-after-free when full sync occurs during a yielding
Lua/function execution.
-- Lena Voytek <email address hidden> Thu, 04 Jun 2026 09:49:21 -0400
|
| 2151296 |
Update Valkey to 7.2.13 in noble, 8.1.7 in questing, and 9.0.4 in resolute and stonking |
| CVE-2026-23479 |
Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `pro |
| CVE-2026-25243 |
Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values |
| CVE-2026-23631 |
Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-repl |
|
|
valkey (8.1.6+dfsg1-0ubuntu0.1) questing; urgency=medium
* New upstream version 8.1.6 (LP: #2142590)
- Security fixes:
+ CVE-2025-67733: RESP Protocol Injection via Lua error_reply.
+ CVE-2026-21863: Remote DoS with malformed Valkey Cluster bus message.
- Bug fixes:
+ Restrict ttl from being negative and avoid crash in import-mode.
+ Fix chained replica crash when doing dual channel replication.
+ Fix used_memory_dataset underflow due to miscalculated
used_memory_overhead.
+ Fix crashing while MODULE UNLOAD when ACL rules reference a module
command or subcommand.
+ Fix server assert on ACL LOAD and resetchannels.
+ Fix bug causing no response flush sometimes when IO threads are busy.
+ Fix Lua VM crash after FUNCTION FLUSH ASYNC + FUNCTION LOAD.
+ Fix invalid memory address caused by hashtable shrinking during safe
iteration.
+ Cluster: Avoid usage of light weight messages to nodes with not ready
bidirectional links.
+ Send duplicate multi meet packet only for node which supports it.
+ Fix loading AOF files from future Valkey versions.
* d/rules: Skip maxmemory unit test during builds as it often times out.
-- Lena Voytek <email address hidden> Tue, 24 Feb 2026 08:49:19 -0500
|
| 2142590 |
Update Valkey to 7.2.12 in noble, 8.1.6 in questing, and 9.0.3 in resolute |
| CVE-2025-67733 |
Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use scripting commands to inject |
| CVE-2026-21863 |
Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious actor with access to the Valkey clusterbus |
|
About
-
Send Feedback to @ubuntu_updates