CVE-2026-82677

NameCVE-2026-82677
DescriptionA vulnerability was determined in valkey-io valkey 9.1.0. Impacted is the function moduleTimerHandler of the file src/module.c of the component Module Timer Subsystem. This manipulation causes double free. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Patch name: b349fe2821e3998534b1454c1b64a478daf8c6b7. To fix this issue, it is recommended to deploy a patch.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1146641

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
valkey (PTS)trixie (security), trixie8.1.1+dfsg1-3+deb13u2vulnerable
forky, sid9.1.2-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
valkeysource(unstable)9.1.2-11146641

Notes

https://github.com/valkey-io/valkey/issues/4200
https://github.com/valkey-io/valkey/pull/4211
Fixed by: https://github.com/valkey-io/valkey/commit/b349fe2821e3998534b1454c1b64a478daf8c6b7 (unstable)
Fixed by: https://github.com/valkey-io/valkey/commit/9461cbaadcf92d090c409fb065ee25afde811221 (9.1.2)
Fixed by: https://github.com/valkey-io/valkey/commit/345a057196edbd94f2f0be87d26a1299fcd95e60 (8.1.10)
check redis, restic?

Search for package or bug name: Reporting problems