Unauthenticated use-after-free of the Lua interpreter state in Valkey (script debugger command cache)
Valkey security advisories
All 12 advisories Valkey has published with an identifier, newest first. Severity is the one its publisher assigned, and the fix is the release the publisher named. Nothing on this page is our judgement.
- Advisories
- 12 10 carry a CVE
- high
- 9
- medium
- 3
- Fix in the archive
- 12 of 12 matched to a release
- Oldest
- 11 Nov 2024 1.8 years ago
Every advisory here is matched to the release in the archive that carries its fix. This page is a copy of what the publisher published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.
Newest first
Every productUse-after-free in the RDMA pending-data handler when a client
UAF in Valkey with TLS may lead to remote code execution
UAF in stream deserialization may lead to remote code execution
RESP Protocol Injection via Lua error_reply
Remote DoS with malformed Valkey Cluster bus message
Pre-Authentication DOS from malformed RESP request
Lua Use-After-Free may lead to remote code execution
DoS Vulnerability due to unlimited growth of output buffers abused by unauthenticated client
Lua library commands may lead to stack overflow and potential RCE
Denial-of-service due to malformed ACL selectors
Denial-of-service due to unbounded pattern matching