Home / mailings [USN-8771-1] Valkey vulnerabilities
Posted on 17 September 2026
Ubuntu Security==========================================================================Ubuntu Security Notice USN-8771-1
September 16, 2026
valkey vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
Summary:
Several security issues were fixed in Valkey.
Software Description:
- valkey: Persistent key-value database with network interface
Details:
Madelyn Olson discovered that Valkey incorrectly handled TLS connections
under certain conditions. A remote attacker could possibly use this issue to
cause Valkey to crash, resulting in a denial of service, or execute arbitrary
code. (CVE-2026-56684)
It was discovered that Valkey incorrectly handled certain stream RDB payloads
when executing the RESTORE command. An authenticated remote attacker could
possibly use this issue to cause Valkey to crash, resulting in a denial
of service, or execute arbitrary code. (CVE-2026-63639)
It was discovered that Valkey incorrectly handled cluster slot migration
operations. A remote attacker could possibly use this issue to cause Valkey
to crash, resulting in a denial of service. This issue was only addressed in
Ubuntu 26.04 LTS. (CVE-2026-85522)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
valkey-tools 9.0.4-0ubuntu0.2
Ubuntu 24.04 LTS
valkey-tools 7.2.13+dfsg1-0ubuntu0.1+esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8771-1
CVE-2026-56684, CVE-2026-63639, CVE-2026-85522
Package Information:
https://launchpad.net/ubuntu/+source/valkey/9.0.4-0ubuntu0.2
--===============5360702190040718312==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
