| Name | CVE-2026-82631 |
| Description | A security flaw has been discovered in valkey-io valkey 9.1.0. The affected element is the function handleClientsBlockedOnKey of the file src/blocked.c of the component Blocked-on-keys Subsystem. The manipulation results in use after free. The attack may be performed from remote. A high complexity level is associated with this attack. The exploitability is described as difficult. The exploit has been released to the public and may be used for attacks. The patch is identified as b2fb0e13f5b4c8c2fb63dcfc2c37a067a0d6d20b. Applying a patch is advised to resolve this issue. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| Debian Bugs | 1146641 |
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|
| redict (PTS) | forky, sid | 7.3.6+ds-3 | vulnerable |
| redis (PTS) | bookworm | 5:7.0.15-1~deb12u7 | vulnerable |
| bookworm (security) | 5:7.0.15-1~deb12u10 | vulnerable |
| trixie | 5:8.0.2-3+deb13u2 | vulnerable |
| trixie (security) | 5:8.0.2-3+deb13u3 | vulnerable |
| forky, sid | 5:8.0.6-3 | vulnerable |
| valkey (PTS) | trixie (security), trixie | 8.1.1+dfsg1-3+deb13u2 | vulnerable |
| forky, sid | 9.1.2-1 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|
| redict | source | (unstable) | (unfixed) | | | |
| redis | source | (unstable) | (unfixed) | | | |
| valkey | source | (unstable) | 9.1.2-1 | | | 1146641 |
Notes
[bookworm] - redis <postponed> (Minor issue; requires a loaded module)
https://github.com/valkey-io/valkey/issues/4198
https://github.com/valkey-io/valkey/pull/4212
Fixed by: https://github.com/valkey-io/valkey/commit/b2fb0e13f5b4c8c2fb63dcfc2c37a067a0d6d20b (unstable)
Fixed by: https://github.com/valkey-io/valkey/commit/e07a231cc607bffd39092efdd2c4344068557a9f (9.1.2)
Fixed by: https://github.com/valkey-io/valkey/commit/f17a71df6ccd9a2476fd7534deb135593a8242bb (8.1.10)
redis is affected by the same flaw and fixed it without a CVE id, by:
https://github.com/redis/redis/commit/a8edcfc98c50bb01c850e5dab3998ce57807144d (#15594)
The fix is present on the redis 7.2 and 8.2 branches but not on 7.0 or 8.0, so all
redis versions in Debian are affected.