{"id":"SUSE-SU-2026:1950-1","summary":"Security update for valkey","details":"This update for valkey fixes the following issues\n\n- CVE-2026-23479: use-after-free in unblock client flow may lead to remote code execution (bsc#1264164).\n- CVE-2026-23631: Lua use-after-free via the master-replica synchronization mechanism may lead to remote code execution\n  (bsc#1264165).\n- CVE-2026-25243: invalid memory access in RESTORE command via a specially crafted serialized payload may lead to remote\n  code execution (bsc#1264166).\n\nChanges for valkey:\n\n  - Update to 8.0.9:\n","modified":"2026-05-19T08:45:10.319238970Z","published":"2026-05-18T07:51:41Z","related":["CVE-2026-23479","CVE-2026-23631","CVE-2026-25243"],"upstream":["CVE-2026-23479","CVE-2026-23631","CVE-2026-25243"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20261950-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264164"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264165"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264166"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23479"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23631"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25243"}],"schema_version":"1.7.5"}