PT-2026-83717 · Valkey Io · Valkey
CVSS v3.1
2.2
Low
| Vector | AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
valkey-io valkey version 9.1.0
Description
A use after free flaw exists in the Blocked-on-keys Subsystem within the
handleClientsBlockedOnKey() function located in the src/blocked.c file. This issue can be triggered remotely, although the attack complexity is high and exploitability is considered difficult.Recommendations
Apply patch b2fb0e13f5b4c8c2fb63dcfc2c37a067a0d6d20b for version 9.1.0.
Exploit
Fix
Buffer Overflow
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Valkey