[ALSA-2025:19675] Important: valkey security update
Type:
security
Severity:
important
Release date:
2025-11-07
Description:
Valkey is an advanced key-value store. It is often referred to as a data structure server since keys can contain strings, hashes, lists, sets and sorted sets. You can run atomic operations on these types, like appending to a string; incrementing the value in a hash; pushing to a list; computing set intersection, union and difference; or getting the member with highest ranking in a sorted set. In order to achieve its outstanding performance, Valkey works with an in-memory dataset. Depending on your use case, you can persist it either by dumping the dataset to disk every once in a while, or by appending each command to a log. Valkey also supports trivial-to-setup master-slave replication, with very fast non-blocking first synchronization, auto-reconnection on net split and so forth. Other features include Transactions, Pub/Sub, Lua scripting, Keys with a limited time-to-live, and configuration settings to make Valkey behave like a cache. You can use Valkey from most programming languages also. Security Fix(es): * redis: Lua library commands may lead to integer overflow and potential RCE (CVE-2025-46817) * Redis: Redis: Authenticated users can execute LUA scripts as a different user (CVE-2025-46818) * Redis: Redis is vulnerable to DoS via specially crafted LUA scripts (CVE-2025-46819) * Redis: Redis Lua Use-After-Free may lead to remote code execution (CVE-2025-49844) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 valkey-devel-8.0.6-1.el10_0.aarch64.rpm 268b81e3f3d583359f6127d0eb36d86eca1255867eb283f77da8f09f92cda2aa
aarch64 valkey-8.0.6-1.el10_0.aarch64.rpm 92d19310a4487f749dae02adab74d79a0239b20ab4ca9b38e5d78faee9b870d4
ppc64le valkey-devel-8.0.6-1.el10_0.ppc64le.rpm cf2fc972e1d981f1fe1ac5b5d2ede9616b958c239a7cf1044bec5eac9bcb1c8e
ppc64le valkey-8.0.6-1.el10_0.ppc64le.rpm f762f2aab506bd36f22de540bed28778c469765dfc94168ea43a6a25efdddc6f
s390x valkey-8.0.6-1.el10_0.s390x.rpm 7405bae61e49838f35e94b1d6d7e9775ae6d0f574b808db9c31e926b329138e4
s390x valkey-devel-8.0.6-1.el10_0.s390x.rpm 9613431050307230d37d03ffa7fd1cf3c67093b507092cf20e528bdb098dc363
x86_64 valkey-8.0.6-1.el10_0.x86_64.rpm 268d22efd800e3dcfcdebaef971721aca49c06cd222fa83a99facb32350d94fc
x86_64 valkey-devel-8.0.6-1.el10_0.x86_64.rpm 55e51e2f907521ef5f5a190c6c7b474871958bdcca0d4522997b601fcd11ea09
x86_64_v2 valkey-8.0.6-1.el10_0.x86_64_v2.rpm 4f7d942d44cfa0799193559473d58149a80d3e3f97992503a6648c6d99ffafcf
x86_64_v2 valkey-devel-8.0.6-1.el10_0.x86_64_v2.rpm 8110b906fee8f14466c9769da98e752c3f7b8d67a40cc0051d3d9a08f476ec80
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.