{"id":"USN-7893-1","summary":"valkey vulnerabilities","details":"Benny Isaacs, Nir Brakha, and Sagi Tzadik discovered that Valkey incorrectly\nhandled memory when running Lua scripts. An authenticated attacker could\nuse this vulnerability to trigger a use-after-free condition, and\npotentially achieve remote code execution on the Valkey server.\n(CVE-2025-49844)\n\nIt was discovered that Valkey incorrectly handled memory when running Lua\nscripts. An authenticated attacker could use this vulnerability to trigger\na integer overflow condition, and potentially achieve remote code execution\non the Valkey server. (CVE-2025-46817)\n\nIt was discovered that Valkey incorrectly handled Lua objects. An\nauthenticated attacker could possibly use this issue to escalate their\nprivileges. (CVE-2025-46818)\n\nIt was discovered that Valkey incorrectly handled memory when running Lua\nscripts. An authenticated attacker could use this vulnerability to read\nout-of-bounds memory, causing a denial of service or possibly obtaining\nsensitive information. (CVE-2025-46819)\n\nIt was discovered that Valkey incorrectly handled memory in some\ncalculations. An attacker could possibly use this issue to cause a denial\nof service. (CVE-2025-49112)","modified":"2026-04-27T17:52:55.763178Z","published":"2025-11-26T13:51:48Z","related":["UBUNTU-CVE-2025-46817","UBUNTU-CVE-2025-46818","UBUNTU-CVE-2025-46819","UBUNTU-CVE-2025-49112","UBUNTU-CVE-2025-49844"],"upstream":["CVE-2025-46817","CVE-2025-46818","CVE-2025-46819","CVE-2025-49112","CVE-2025-49844","UBUNTU-CVE-2025-46817","UBUNTU-CVE-2025-46818","UBUNTU-CVE-2025-46819","UBUNTU-CVE-2025-49112","UBUNTU-CVE-2025-49844"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-7893-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-46817"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-46818"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-46819"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-49112"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-49844"}],"affected":[{"package":{"name":"valkey","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/valkey@7.2.11+dfsg1-0ubuntu0.2?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.2.11+dfsg1-0ubuntu0.2"}]}],"versions":["7.2.5+dfsg1-2ubuntu4~24.04.1","7.2.7+dfsg1-0ubuntu0.24.04.1","7.2.8+dfsg1-0ubuntu0.24.04.1","7.2.8+dfsg1-0ubuntu0.24.04.2","7.2.8+dfsg1-0ubuntu0.24.04.3","7.2.10+dfsg1-0ubuntu0.1","7.2.11+dfsg1-0ubuntu0.1"],"ecosystem_specific":{"binaries":[{"binary_name":"valkey-redis-compat","binary_version":"7.2.11+dfsg1-0ubuntu0.2"},{"binary_name":"valkey-sentinel","binary_version":"7.2.11+dfsg1-0ubuntu0.2"},{"binary_name":"valkey-server","binary_version":"7.2.11+dfsg1-0ubuntu0.2"},{"binary_name":"valkey-tools","binary_version":"7.2.11+dfsg1-0ubuntu0.2"}],"availability":"No subscription required"},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:24.04:LTS","cves":[{"id":"CVE-2025-46817","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2025-46818","severity":[{"score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2025-46819","severity":[{"score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2025-49112","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"score":"medium","type":"Ubuntu"}]},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"},{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"high"}],"id":"CVE-2025-49844"}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7893-1.json"}},{"package":{"name":"valkey","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/valkey@8.1.4+dfsg1-0ubuntu0.2?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.1.4+dfsg1-0ubuntu0.2"}]}],"versions":["8.0.2+dfsg1-1ubuntu1","8.1.1+dfsg1-2ubuntu1","8.1.3+dfsg1-0ubuntu1","8.1.3+dfsg1-0ubuntu2","8.1.4+dfsg1-0ubuntu0.1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_version":"8.1.4+dfsg1-0ubuntu0.2","binary_name":"valkey-sentinel"},{"binary_version":"8.1.4+dfsg1-0ubuntu0.2","binary_name":"valkey-server"},{"binary_name":"valkey-tools","binary_version":"8.1.4+dfsg1-0ubuntu0.2"}]},"database_specific":{"cves_map":{"cves":[{"id":"CVE-2025-46817","severity":[{"score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2025-46818","severity":[{"score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2025-46819","severity":[{"score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2025-49112","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2025-49844","severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"high","type":"Ubuntu"}]}],"ecosystem":"Ubuntu:25.10"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7893-1.json"}}],"schema_version":"1.7.5"}