CVE-2026-82631

NameCVE-2026-82631
DescriptionA security flaw has been discovered in valkey-io valkey 9.1.0. The affected element is the function handleClientsBlockedOnKey of the file src/blocked.c of the component Blocked-on-keys Subsystem. The manipulation results in use after free. The attack may be performed from remote. A high complexity level is associated with this attack. The exploitability is described as difficult. The exploit has been released to the public and may be used for attacks. The patch is identified as b2fb0e13f5b4c8c2fb63dcfc2c37a067a0d6d20b. Applying a patch is advised to resolve this issue.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1146641

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
valkey (PTS)trixie (security), trixie8.1.1+dfsg1-3+deb13u2vulnerable
forky, sid9.1.2-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
valkeysource(unstable)9.1.2-11146641

Notes

https://github.com/valkey-io/valkey/issues/4198
https://github.com/valkey-io/valkey/pull/4212
Fixed by: https://github.com/valkey-io/valkey/commit/b2fb0e13f5b4c8c2fb63dcfc2c37a067a0d6d20b (unstable)
Fixed by: https://github.com/valkey-io/valkey/commit/e07a231cc607bffd39092efdd2c4344068557a9f (9.1.2)
Fixed by: https://github.com/valkey-io/valkey/commit/f17a71df6ccd9a2476fd7534deb135593a8242bb (8.1.10)
check resis and restic

Search for package or bug name: Reporting problems