| Name | CVE-2026-82677 |
| Description | A vulnerability was determined in valkey-io valkey 9.1.0. Impacted is the function moduleTimerHandler of the file src/module.c of the component Module Timer Subsystem. This manipulation causes double free. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Patch name: b349fe2821e3998534b1454c1b64a478daf8c6b7. To fix this issue, it is recommended to deploy a patch. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| Debian Bugs | 1146641 |
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|
| redict (PTS) | forky, sid | 7.3.6+ds-3 | vulnerable |
| redis (PTS) | bookworm | 5:7.0.15-1~deb12u7 | vulnerable |
| bookworm (security) | 5:7.0.15-1~deb12u10 | vulnerable |
| trixie | 5:8.0.2-3+deb13u2 | vulnerable |
| trixie (security) | 5:8.0.2-3+deb13u3 | vulnerable |
| forky, sid | 5:8.0.6-3 | vulnerable |
| valkey (PTS) | trixie (security), trixie | 8.1.1+dfsg1-3+deb13u2 | vulnerable |
| forky, sid | 9.1.2-1 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|
| redict | source | (unstable) | (unfixed) | | | |
| redis | source | (unstable) | (unfixed) | | | |
| valkey | source | (unstable) | 9.1.2-1 | | | 1146641 |
Notes
[bookworm] - redis <postponed> (Minor issue; requires a loaded module)
https://github.com/valkey-io/valkey/issues/4200
https://github.com/valkey-io/valkey/pull/4211
Fixed by: https://github.com/valkey-io/valkey/commit/b349fe2821e3998534b1454c1b64a478daf8c6b7 (unstable)
Fixed by: https://github.com/valkey-io/valkey/commit/9461cbaadcf92d090c409fb065ee25afde811221 (9.1.2)
Fixed by: https://github.com/valkey-io/valkey/commit/345a057196edbd94f2f0be87d26a1299fcd95e60 (8.1.10)
redis shares this flaw and is unfixed upstream: moduleTimerHandler() removes and frees
the timer after the callback returns, even when the callback already stopped it through
RM_StopTimer(). Reproduced on redis 8.0.2 with a module whose timer callback stops
its own timer: "free(): double free detected in tcache 2". The same unconditional
free after the callback is present on the redis 7.2, 8.0 and unstable branches.