{"id":"RHSA-2026:64807","summary":"Red Hat Security Advisory: valkey security, bug fix, and enhancement update","modified":"2026-09-09T10:20:11Z","published":"2026-09-08T10:19:12Z","upstream":["CVE-2026-56684","CVE-2026-63639","CVE-2026-66373"],"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:64807"},{"type":"ARTICLE","url":"https://access.redhat.com/security/updates/classification/#important"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2506985"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517906"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2517907"},{"type":"ARTICLE","url":"https://issues.redhat.com/browse/RHEL-216778"},{"type":"ADVISORY","url":"https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_64807.json"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-56684"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-56684"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-56684"},{"type":"ARTICLE","url":"https://github.com/valkey-io/valkey/commit/7cd5bcb7575d750ec2de618db80da58680a10fe3"},{"type":"ARTICLE","url":"https://github.com/valkey-io/valkey/pull/4234"},{"type":"ARTICLE","url":"https://github.com/valkey-io/valkey/releases/tag/7.2.14"},{"type":"ARTICLE","url":"https://github.com/valkey-io/valkey/releases/tag/8.0.10"},{"type":"ARTICLE","url":"https://github.com/valkey-io/valkey/releases/tag/8.1.9"},{"type":"ARTICLE","url":"https://github.com/valkey-io/valkey/releases/tag/9.0.5"},{"type":"ARTICLE","url":"https://github.com/valkey-io/valkey/releases/tag/9.1.1"},{"type":"ARTICLE","url":"https://github.com/valkey-io/valkey/security/advisories/GHSA-53mc-f3m3-99vh"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-63639"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-63639"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63639"},{"type":"ARTICLE","url":"https://github.com/valkey-io/valkey/commit/06bc7768fe609f2054e69ccedefe7628f5675da9"},{"type":"ARTICLE","url":"https://github.com/valkey-io/valkey/commit/509cb3c74e8cbc9c0498ebe8b6c93dcd605e7271"},{"type":"ARTICLE","url":"https://github.com/valkey-io/valkey/commit/98465eaffe3f95524a5046318bfbc4bdb9798291"},{"type":"ARTICLE","url":"https://github.com/valkey-io/valkey/commit/e95911d4d65be8789fa3705f44d7ed1e65378445"},{"type":"ARTICLE","url":"https://github.com/valkey-io/valkey/commit/f8d2027e8d4df790ac04974bf606408c8ea62778"},{"type":"ARTICLE","url":"https://github.com/valkey-io/valkey/pull/4073"},{"type":"ARTICLE","url":"https://github.com/valkey-io/valkey/security/advisories/GHSA-mvcj-73cw-22m4"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-66373"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-66373"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-66373"},{"type":"ARTICLE","url":"https://github.com/berabuddies/redis-poc"},{"type":"ARTICLE","url":"https://github.com/redis/redis/compare/8.6.4...8.8.0"},{"type":"ARTICLE","url":"https://github.com/redis/redis/pull/15081"},{"type":"ARTICLE","url":"https://news.ycombinator.com/item?id=49024938"},{"type":"ARTICLE","url":"https://x.com/Fried_rice/status/2080059356322918777"}],"affected":[{"package":{"name":"valkey","ecosystem":"Red Hat:enterprise_linux:9::appstream","purl":"pkg:rpm/redhat/valkey"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:8.0.10-1.el9_8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:64807.json"}},{"package":{"name":"valkey-debuginfo","ecosystem":"Red Hat:enterprise_linux:9::appstream","purl":"pkg:rpm/redhat/valkey-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:8.0.10-1.el9_8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:64807.json"}},{"package":{"name":"valkey-debugsource","ecosystem":"Red Hat:enterprise_linux:9::appstream","purl":"pkg:rpm/redhat/valkey-debugsource"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:8.0.10-1.el9_8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:64807.json"}},{"package":{"name":"valkey-devel","ecosystem":"Red Hat:enterprise_linux:9::appstream","purl":"pkg:rpm/redhat/valkey-devel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:8.0.10-1.el9_8"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:64807.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}