UbuntuUpdates.org

Package "valkey"

Name: valkey

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • Persistent key-value database with network interface (monitoring)
  • Persistent key-value database with network interface
  • Persistent key-value database with network interface (client)

Latest version: 8.1.4+dfsg1-0ubuntu0.1
Release: questing (25.10)
Level: updates
Repository: universe

Links



Other versions of "valkey" in Questing

Repository Area Version
base universe 8.1.3+dfsg1-0ubuntu2
proposed universe 8.1.4+dfsg1-0ubuntu0.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 8.1.4+dfsg1-0ubuntu0.1 2025-11-13 01:07:25 UTC

  valkey (8.1.4+dfsg1-0ubuntu0.1) questing; urgency=medium

  * New upstream version 8.1.4 (LP: #2127122)
    - Security fixes:
      + CVE-2025-49844: Lua script may lead to remote code execution.
      + CVE-2025-46817: Lua script may lead to int overflow and potential RCE.
      + CVE-2025-46818: Lua script can be executed in context of another user.
      + CVE-2025-46819: LUA out-of-bound read
      + CVE-2025-49112: Integer underflow in setDeferredReply networking.c.
    - Bug fixes:
      + Fix accounting for dual channel RDB bytes in replication stats.
      + Ensure empty error tables in scripts don't crash Valkey.
      + Fix use-after-free when active expiration triggers hashtable to shrink.
      + Fix memory usage to consider embedded keys.
      + Fix leak when shrinking a hashtable without entries.
      + Fix large allocations crashing Valkey during active defrag.
      + Prevent bad memory access when NOTOUCH client gets unblocked.
      + Converge shard-id persisted in nodes.conf to primary's shard id.
      + Fix client tracking memory overhead calculation.
      + Fix pre-size hashtables per slot when reading RDB files.
      + Don't use AVX2 instructions if the CPU don't support it.
      + Defrag if slab 1/8 full to fix defrag didn't stop issue.
  * Remove patches fixed upstream:
    - d/p/CVE-2025-49112.patch
    - d/p/fix-8.1.x-multi-unit-test.patch

 -- Lena Voytek <email address hidden> Sat, 11 Oct 2025 22:37:19 -0400

2127122 Update Valkey to 7.2.11 in noble, 8.0.6 in plucky, and 8.1.4 in questing + resolute
CVE-2025-49844 Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lu
CVE-2025-46817 Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lu
CVE-2025-46818 Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted Lu
CVE-2025-46819 Redis is an open source, in-memory database that persists on disk. Versions 8.2.1 and below allow an authenticated user to use a specially crafted LU
CVE-2025-49112 setDeferredReply in networking.c in Valkey through 8.1.1 has an integer underflow for prev->size - prev->used.



About   -   Send Feedback to @ubuntu_updates