[ALSA-2025:21916] Important: valkey security update
Type:
security
Severity:
important
Release date:
2025-12-01
Description:
Valkey is an advanced key-value store. It is often referred to as a data structure server since keys can contain strings, hashes, lists, sets and sorted sets. You can run atomic operations on these types, like appending to a string; incrementing the value in a hash; pushing to a list; computing set intersection, union and difference; or getting the member with highest ranking in a sorted set. In order to achieve its outstanding performance, Valkey works with an in-memory dataset. Depending on your use case, you can persist it either by dumping the dataset to disk every once in a while, or by appending each command to a log. Valkey also supports trivial-to-setup master-slave replication, with very fast non-blocking first synchronization, auto-reconnection on net split and so forth. Other features include Transactions, Pub/Sub, Lua scripting, Keys with a limited time-to-live, and configuration settings to make Valkey behave like a cache. You can use Valkey from most programming languages also. Security Fix(es): * redis: Lua library commands may lead to integer overflow and potential RCE (CVE-2025-46817) * Redis: Redis: Authenticated users can execute LUA scripts as a different user (CVE-2025-46818) * Redis: Redis is vulnerable to DoS via specially crafted LUA scripts (CVE-2025-46819) * Redis: Redis Lua Use-After-Free may lead to remote code execution (CVE-2025-49844) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 valkey-8.0.6-2.el9_7.aarch64.rpm 747e5bfb0162982bddf3824a6d53e1986bc5f9a0d1efe8bcfd99f8997cc6bdf2
aarch64 valkey-devel-8.0.6-2.el9_7.aarch64.rpm 8ac7b40782e9822e61d5720e039ebc8ade52569cb886165554faaa4c67408c6d
ppc64le valkey-8.0.6-2.el9_7.ppc64le.rpm abc77691baf55fa43b9d7b9c1d686fd87ac3ddacdde35813ff915e20611c9a2f
ppc64le valkey-devel-8.0.6-2.el9_7.ppc64le.rpm f216841b48850886ca2a79dd3e11881e81094f283d5c4b7210c1ad0b6dfab61d
s390x valkey-8.0.6-2.el9_7.s390x.rpm 8b4306c739bf562898bbf3ba445087761574fbd43bca897845cd9026b4f72433
s390x valkey-devel-8.0.6-2.el9_7.s390x.rpm b0455464ba489f132cf0796cc81a64c3688c110a64087c3516f10b35ed71880a
x86_64 valkey-8.0.6-2.el9_7.x86_64.rpm 83471ca3312b3f1eca41af77f0df7ce98b97634a4e397d91cf67450bb380b8b4
x86_64 valkey-devel-8.0.6-2.el9_7.x86_64.rpm e5adabd7532ced40283696492e9ce8eb15ea843291ea0b6c3e014ae9ba03d3b0
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.