UbuntuUpdates.org

Package "valkey"


Moved to questing:universe:updates


Name: valkey

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • Persistent key-value database with network interface (monitoring)
  • Persistent key-value database with network interface
  • Persistent key-value database with network interface (client)

Latest version: *DELETED*
Release: questing (25.10)
Level: proposed
Repository: universe

Links



Other versions of "valkey" in Questing

Repository Area Version
base universe 8.1.3+dfsg1-0ubuntu2
security universe 8.1.6+dfsg1-0ubuntu0.1
updates universe 8.1.7+dfsg1-0ubuntu0.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: *DELETED* 2026-07-09 20:08:37 UTC
Moved to questing:universe:updates
No changelog for deleted or moved packages.

Version: 8.1.7+dfsg1-0ubuntu0.1 2026-06-30 21:07:25 UTC

  valkey (8.1.7+dfsg1-0ubuntu0.1) questing; urgency=medium

  * New upstream version 8.1.7 (LP: #2151296)
    - Security fixes:
      + CVE-2026-23479: Use-After-Free in unblock client flow.
      + CVE-2026-25243: Invalid Memory Access in RESTORE command.
      + CVE-2026-23631: Use-after-free when full sync occurs during a yielding
        Lua/function execution.

 -- Lena Voytek <email address hidden> Thu, 04 Jun 2026 09:49:21 -0400

2151296 Update Valkey to 7.2.13 in noble, 8.1.7 in questing, and 9.0.4 in resolute and stonking
CVE-2026-23479 Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `pro
CVE-2026-25243 Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values
CVE-2026-23631 Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-repl

Version: *DELETED* 2026-03-16 20:09:00 UTC
Moved to questing:universe:updates
No changelog for deleted or moved packages.

Version: 8.1.6+dfsg1-0ubuntu0.1 2026-03-04 00:08:29 UTC

  valkey (8.1.6+dfsg1-0ubuntu0.1) questing; urgency=medium

  * New upstream version 8.1.6 (LP: #2142590)
    - Security fixes:
        + CVE-2025-67733: RESP Protocol Injection via Lua error_reply.
        + CVE-2026-21863: Remote DoS with malformed Valkey Cluster bus message.
    - Bug fixes:
        + Restrict ttl from being negative and avoid crash in import-mode.
        + Fix chained replica crash when doing dual channel replication.
        + Fix used_memory_dataset underflow due to miscalculated
          used_memory_overhead.
        + Fix crashing while MODULE UNLOAD when ACL rules reference a module
          command or subcommand.
        + Fix server assert on ACL LOAD and resetchannels.
        + Fix bug causing no response flush sometimes when IO threads are busy.
        + Fix Lua VM crash after FUNCTION FLUSH ASYNC + FUNCTION LOAD.
        + Fix invalid memory address caused by hashtable shrinking during safe
          iteration.
        + Cluster: Avoid usage of light weight messages to nodes with not ready
          bidirectional links.
        + Send duplicate multi meet packet only for node which supports it.
        + Fix loading AOF files from future Valkey versions.
  * d/rules: Skip maxmemory unit test during builds as it often times out.

 -- Lena Voytek <email address hidden> Tue, 24 Feb 2026 08:49:19 -0500

2142590 Update Valkey to 7.2.12 in noble, 8.1.6 in questing, and 9.0.3 in resolute
CVE-2025-67733 Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious user can use scripting commands to inject
CVE-2026-21863 Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious actor with access to the Valkey clusterbus

Version: *DELETED* 2025-11-13 20:07:55 UTC
Moved to questing:universe:updates
No changelog for deleted or moved packages.



About   -   Send Feedback to @ubuntu_updates