Bug 2526157 (CVE-2026-82631) - CVE-2026-82631 valkey: Valkey: Use-after-free vulnerability in Blocked-on-keys subsystem
Summary: CVE-2026-82631 valkey: Valkey: Use-after-free vulnerability in Blocked-on-key...
Keywords:
Status: NEW
Alias: CVE-2026-82631
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-31 08:11 UTC by OSIDB Bzimport
Modified: 2026-09-15 15:40 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-31 08:11:21 UTC
A security flaw has been discovered in valkey-io valkey 9.1.0. The affected element is the function handleClientsBlockedOnKey of the file src/blocked.c of the component Blocked-on-keys Subsystem. The manipulation results in use after free. The attack may be performed from remote. A high complexity level is associated with this attack. The exploitability is described as difficult. The exploit has been released to the public and may be used for attacks. The patch is identified as b2fb0e13f5b4c8c2fb63dcfc2c37a067a0d6d20b. Applying a patch is advised to resolve this issue.


Note You need to log in before you can comment on or make changes to this bug.