{"id":"openSUSE-SU-2026:20776-1","summary":"Security update for valkey","details":"This update for valkey fixes the following issues\n\n- CVE-2025-67733: data tampering and denial of service via improper null character handling in Lua scripts\n  (bsc#1258746).\n- CVE-2026-21863: denial of service via invalid clusterbus packet (bsc#1258788).\n- CVE-2026-23479: use-after-free in unblock client flow may lead to remote code execution (bsc#1264164).\n- CVE-2026-23631: Lua use-after-free via the master-replica synchronization mechanism may lead to remote code execution\n  (bsc#1264165).\n- CVE-2026-25243: invalid memory access in RESTORE command via a specially crafted serialized payload may lead to remote\n  code execution (bsc#1264166).\n\nChanges for valkey:\n\n  - Update to 8.0.9.\n\n  - Update to 8.0.7:\n\n   * Fix ltrim should not call signalModifiedKey when no elements are removed (#2787)\n   * Fix chained replica crash when doing dual channel replication (#2983)\n   * Fix used_memory_dataset underflow due to miscalculated used_memory_overhead (#3005)\n   * Avoids crash during MODULE UNLOAD when ACL rules reference a module command and\n     subcommand (#3160)\n   * Fix server assert on ACL LOAD and resetchannels (#3182)\n   * Fix bug causing no response flush sometimes when IO threads are busy (#3205)\n","modified":"2026-05-26T18:24:19.174868367Z","published":"2026-05-18T10:01:17Z","related":["CVE-2025-67733","CVE-2026-21863","CVE-2026-23479","CVE-2026-23631","CVE-2026-25243"],"upstream":["CVE-2025-67733","CVE-2026-21863","CVE-2026-23479","CVE-2026-23631","CVE-2026-25243"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258746"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258788"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264164"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264165"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264166"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-67733"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21863"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23479"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23631"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25243"}],"schema_version":"1.7.5"}