CVE-2026-82677

NameCVE-2026-82677
DescriptionA vulnerability was determined in valkey-io valkey 9.1.0. Impacted is the function moduleTimerHandler of the file src/module.c of the component Module Timer Subsystem. This manipulation causes double free. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Patch name: b349fe2821e3998534b1454c1b64a478daf8c6b7. To fix this issue, it is recommended to deploy a patch.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1146641

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
redict (PTS)forky, sid7.3.6+ds-3vulnerable
redis (PTS)bookworm5:7.0.15-1~deb12u7vulnerable
bookworm (security)5:7.0.15-1~deb12u10vulnerable
trixie5:8.0.2-3+deb13u2vulnerable
trixie (security)5:8.0.2-3+deb13u3vulnerable
forky, sid5:8.0.6-3vulnerable
valkey (PTS)trixie (security), trixie8.1.1+dfsg1-3+deb13u2vulnerable
forky, sid9.1.2-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
redictsource(unstable)(unfixed)
redissource(unstable)(unfixed)
valkeysource(unstable)9.1.2-11146641

Notes

[bookworm] - redis <postponed> (Minor issue; requires a loaded module)
https://github.com/valkey-io/valkey/issues/4200
https://github.com/valkey-io/valkey/pull/4211
Fixed by: https://github.com/valkey-io/valkey/commit/b349fe2821e3998534b1454c1b64a478daf8c6b7 (unstable)
Fixed by: https://github.com/valkey-io/valkey/commit/9461cbaadcf92d090c409fb065ee25afde811221 (9.1.2)
Fixed by: https://github.com/valkey-io/valkey/commit/345a057196edbd94f2f0be87d26a1299fcd95e60 (8.1.10)
redis shares this flaw and is unfixed upstream: moduleTimerHandler() removes and frees
the timer after the callback returns, even when the callback already stopped it through
RM_StopTimer(). Reproduced on redis 8.0.2 with a module whose timer callback stops
its own timer: "free(): double free detected in tcache 2". The same unconditional
free after the callback is present on the redis 7.2, 8.0 and unstable branches.

Search for package or bug name: Reporting problems