#1147517 valkey: CVE-2026-86227

Package:
src:valkey
Source:
src:valkey
Submitter:
Salvatore Bonaccorso
Date:
2026-09-13 03:21:02 UTC
Severity:
normal
Tags:
#1147517#5
Date:
2026-09-12 15:11:57 UTC
From:
To:
Hi,

The following vulnerability was published for valkey.

CVE-2026-86227[0]:
| A weakness has been identified in valkey-io valkey up to
| 9.0.5/9.1.1. This affects the function kvstoreGetHashtable of the
| file src/kvstore.c. This manipulation of the argument didx causes
| out-of-bounds read. It is possible to initiate the attack remotely.
| The attack is considered to have high complexity. It is indicated
| that the exploitability is difficult. The exploit has been made
| available to the public and could be used for attacks. Patch name:
| 4691888e7fab3df128f0bde5750c9fde2ae552fa. To fix this issue, it is
| recommended to deploy a patch. Exploitation requires cluster mode
| plus attacker-controlled dump.rdb at startup (data-dir write access,
| replication feed, or a stored crafted RDB) - an attacker-position
| DoS at boot, not network pre-auth. The issue report was closed
| stating it "is worth fixing for the sake of memory safety… but I
| don't think it meets our bar for a security disclosure."


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-86227
https://www.cve.org/CVERecord?id=CVE-2026-86227
[1] https://github.com/valkey-io/valkey/issues/4222
[2] https://github.com/valkey-io/valkey/pull/4229
[3] https://github.com/valkey-io/valkey/commit/015c4d84682a6b214f1c8e6d502668cb51653860

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1147517#10
Date:
2026-09-13 03:18:56 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
valkey, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1147517@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Lena Voytek <lena@debian.org> (supplier of updated valkey package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 12 Sep 2026 22:36:42 -0400
Source: valkey
Built-For-Profiles: derivative.ubuntu noudeb
Architecture: source
Version: 9.1.2-1
Distribution: unstable
Urgency: medium
Maintainer: Lucas Kanashiro <kanashiro@debian.org>
Changed-By: Lena Voytek <lena@debian.org>
Closes: 1146641 1146879 1147517
Changes:
 valkey (9.1.2-1) unstable; urgency=medium
 .
   * New upstream version 9.1.2 (Closes: #1146641, #1146879, #1147517).
     - Fix CVE-2026-82631, CVE-2026-82677, CVE-2026-85522, and CVE-2026-86227.
   * Remove 0006-Fix-test-cert-gen-and-tls-tests.patch - fixed upstream.
Checksums-Sha1:
 e92e3285066c438db99c850c802949379c3340e5 2251 valkey_9.1.2-1.dsc
 f9faa46df0782fe6237dd977b3074c5316df3558 4418246 valkey_9.1.2.orig.tar.gz
 d6c9e76f01c389d1d1188bc13581c05022a3d930 17752 valkey_9.1.2-1.debian.tar.xz
 8d715f036d8eb8d654520cdd1af81722a75e9dc4 8464 valkey_9.1.2-1_source.buildinfo
Checksums-Sha256:
 637995b2db343b75ae655fdb458b1f14f9b9b6f913f6144bdb9764b51b2ce2b2 2251 valkey_9.1.2-1.dsc
 8e8557da7426a51b4e0fb514a65ef6241dc7c85cb408243af389070abf379cec 4418246 valkey_9.1.2.orig.tar.gz
 e83701e1f5140721fe85cbe11bfdbf9b4bb841b6d423644977fbfd2ee417a629 17752 valkey_9.1.2-1.debian.tar.xz
 bb82088b64d672cfde1a4bf2c25bdf8ad0a544a53733bc69646c1e175336aede 8464 valkey_9.1.2-1_source.buildinfo
Files:
 78f2270d238ad42769b1e8ab06c68f02 2251 database optional valkey_9.1.2-1.dsc
 2f87e9ed4a98c093d85e2f90474498a7 4418246 database optional valkey_9.1.2.orig.tar.gz
 a641efebc34cb3f65c19782738c9f5eb 17752 database optional valkey_9.1.2-1.debian.tar.xz
 eb399451c70619dd7efa43e9b6b3b46f 8464 database optional valkey_9.1.2-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQJEBAEBCgAuFiEEY+78PeFNUUbOfyS/NLitfZUp55MFAmqmEiEQHGxlbmFAZGVi
aWFuLm9yZwAKCRA0uK19lSnnk0glD/9zXNHyWCw+GsP61xKT+KSsW2Zvt0KEMH7N
fplzkIp505A0MU14Q8PWuytthe+kCe1QbsuxmNYAf+WWuY863W0RkK1qan55Go2/
YR53PE25ycIuoHDGI6ISDJJO0qy6AvcPtPAXf2iqnLt3ZlFx1+d/pK10oGh6x5hQ
jA3pJihYREolGk6Q2IMElQ85bXruvQYdxdAhN+OiZlktUYD4b1oPoNCK2tWJc3Jt
MnFqydMEAHnszL+q2SfPZ/U1TopmDpgafsEI9dFAk/fc1v/VY9WL3PoYRlVZAR4g
D3MPuf1d66lkdMrKqwr95kxx6sU/H0yNdJFBvHMbP+OOylJshDlHBb44dyYVcQyv
6ZWUSkh9mUA/1e/MaayO0M63V+vLsXEz+m+WnbCoNBc+Vv58snA4+G1iubG0GKRK
MnGp6uTt3RmfEv5BC2OiJsZqJsZ9d2VeTzv3htbQ0t5D1l5z1NKoMInmpuizeqie
Z3oCUuTKVbNKRo9HYxVgdB4omCRh9RgaO4w35TTYWNPA2tTrAEGRSe+yE5ysMeKQ
IOSol+vKEkvFv08ze3Ok5kSo6mC2d5cqRNPo3nv7I3UVyzxReSqJes9Ws7Znmymk
ytAEI85u9jLOnnSLpWDGoryDpSpkm/uhmKrNFFStDmOqNhRpqrWweLO8Nh/g2iaC
Zd0x20ETNg==
=TZ+V
-----END PGP SIGNATURE-----