<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 14:54:11 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:64796 — Important: valkey security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:64796</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: valkey, AlmaLinux:10: valkey-devel&lt;/p&gt;
&lt;p&gt;Valkey is an advanced key-value store. It is often referred to as a data structure server since keys can contain strings, hashes, lists, sets and sorted sets. You can run atomic operations on these types, like appending to a string; incrementing the value in a hash; pushing to a list; computing set intersection, union and difference; or getting the member with highest ranking in a sorted set. In order to achieve its outstanding performance, Valkey works with an in-memory dataset. Depending on your use case, you can persist it either by dumping the dataset to disk every once in a while, or by appending each command to a log. Valkey also supports trivial-to-setup master-slave replication, with very fast non-blocking first synchronization, auto-reconnection on net split and so forth. Other features include Transactions, Pub/Sub, Lua scripting, Keys with a limited time-to-live, and configuration settings to make Valkey behave like a cache. You can use Valkey from most programming languages also.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* redis: Redis: Remote Code Execution via specially crafted RESTORE payload (CVE-2026-66373)
  * valkey: Valkey: Remote code execution via use-after-free in stream deserialization (CVE-2026-63639)
  * valkey: Valkey: Remote code execution via TLS pending-data processing use-after-free (CVE-2026-56684)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* [Tracker] Rebase valkey to 8.0.10 (JIRA:AlmaLinux-216776)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the im…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: valkey, AlmaLinux:10: valkey-devel&lt;/p&gt;
&lt;p&gt;Valkey is an advanced key-value store. It is often referred to as a data structure server since keys can contain strings, hashes, lists, sets and sorted sets. You can run atomic operations on these types, like appending to a string; incrementing the value in a hash; pushing to a list; computing set intersection, union and difference; or getting the member with highest ranking in a sorted set. In order to achieve its outstanding performance, Valkey works with an in-memory dataset. Depending on your use case, you can persist it either by dumping the dataset to disk every once in a while, or by appending each command to a log. Valkey also supports trivial-to-setup master-slave replication, with very fast non-blocking first synchronization, auto-reconnection on net split and so forth. Other features include Transactions, Pub/Sub, Lua scripting, Keys with a limited time-to-live, and configuration settings to make Valkey behave like a cache. You can use Valkey from most programming languages also.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* redis: Redis: Remote Code Execution via specially crafted RESTORE payload (CVE-2026-66373)
  * valkey: Valkey: Remote code execution via use-after-free in stream deserialization (CVE-2026-63639)
  * valkey: Valkey: Remote code execution via TLS pending-data processing use-after-free (CVE-2026-56684)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* [Tracker] Rebase valkey to 8.0.10 (JIRA:AlmaLinux-216776)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the im…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:64796</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-63639</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-63639</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: redis, Alpaquita:25: valkey, Alpaquita:stream: valkey&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: redis, Alpaquita:25: valkey, Alpaquita:stream: valkey&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-63639</guid>
    </item>
    <item>
      <title>BIT-valkey-2026-63639 — Valkey: UAF in stream deserialization may lead to remote code execution</title>
      <link>https://cve.radiocsirt.org/vuln/bit-valkey-2026-63639</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: valkey&lt;/p&gt;
&lt;p&gt;Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey&amp;#39;s RESTORE command accepts a malformed RDB stream payload that assigns one Pending Entry List NACK to multiple consumers during stream consumer-group deserialization, causing a use-after-free when one consumer is deleted while another still references the shared NACK and potentially allowing remote code execution. This issue is fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: valkey&lt;/p&gt;
&lt;p&gt;Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey&amp;#39;s RESTORE command accepts a malformed RDB stream payload that assigns one Pending Entry List NACK to multiple consumers during stream consumer-group deserialization, causing a use-after-free when one consumer is deleted while another still references the shared NACK and potentially allowing remote code execution. This issue is fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-valkey-2026-63639</guid>
    </item>
    <item>
      <title>EUVD-2026-357025</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-357025</link>
      <description>EUVD-2026-357025</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-357025</guid>
    </item>
    <item>
      <title>fkie_cve-2026-63639</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-63639</link>
      <description>&lt;p&gt;Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey&amp;#39;s RESTORE command accepts a malformed RDB stream payload that assigns one Pending Entry List NACK to multiple consumers during stream consumer-group deserialization, causing a use-after-free when one consumer is deleted while another still references the shared NACK and potentially allowing remote code execution. This issue is fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey&amp;#39;s RESTORE command accepts a malformed RDB stream payload that assigns one Pending Entry List NACK to multiple consumers during stream consumer-group deserialization, causing a use-after-free when one consumer is deleted while another still references the shared NACK and potentially allowing remote code execution. This issue is fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-63639</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-63639 — Valkey: UAF in stream deserialization may lead to remote code execution</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-63639</link>
      <description>msrc_CVE-2026-63639</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-63639</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11381-1 — valkey-9.1.1-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11381-1</link>
      <description>&lt;p&gt;valkey-9.1.1-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;valkey-9.1.1-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11381-1</guid>
    </item>
    <item>
      <title>RHSA-2026:61884 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:61884</link>
      <description>&lt;p&gt;valkey: Valkey: Remote code execution via TLS pending-data processing use-after-free valkey: Valkey: Remote code execution via use-after-free in stream deserialization valkey: Valkey: Use-after-free vulnerability in Blocked-on-keys subsystem valkey: Valkey: Denial of Service via double free in Module Timer subsystem&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;valkey: Valkey: Remote code execution via TLS pending-data processing use-after-free valkey: Valkey: Remote code execution via use-after-free in stream deserialization valkey: Valkey: Use-after-free vulnerability in Blocked-on-keys subsystem valkey: Valkey: Denial of Service via double free in Module Timer subsystem&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:61884</guid>
    </item>
    <item>
      <title>RLSA-2026:64796 — Important: valkey security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:64796</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: valkey&lt;/p&gt;
&lt;p&gt;Valkey is an advanced key-value store. It is often referred to as a data structure server since keys can contain strings, hashes, lists, sets and sorted sets.  You can run atomic operations on these types, like appending to a string; incrementing the value in a hash; pushing to a list; computing set intersection, union and difference; or getting the member with highest ranking in a sorted set.  In order to achieve its outstanding performance, Valkey works with an in-memory dataset. Depending on your use case, you can persist it either by dumping the dataset to disk every once in a while, or by appending each command to a log.  Valkey also supports trivial-to-setup master-slave replication, with very fast non-blocking first synchronization, auto-reconnection on net split and so forth.  Other features include Transactions, Pub/Sub, Lua scripting, Keys with a limited time-to-live, and configuration settings to make Valkey behave like a cache.  You can use Valkey from most programming languages also.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* redis: Redis: Remote Code Execution via specially crafted RESTORE payload (CVE-2026-66373)&lt;/p&gt;
&lt;p&gt;* valkey: Valkey: Remote code execution via use-after-free in stream deserialization (CVE-2026-63639)&lt;/p&gt;
&lt;p&gt;* valkey: Valkey: Remote code execution via TLS pending-data processing use-after-free (CVE-2026-56684)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* [Tracker] Rebase valkey to 8.0.10 (JIRA:Rocky Linux-216776)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: valkey&lt;/p&gt;
&lt;p&gt;Valkey is an advanced key-value store. It is often referred to as a data structure server since keys can contain strings, hashes, lists, sets and sorted sets.  You can run atomic operations on these types, like appending to a string; incrementing the value in a hash; pushing to a list; computing set intersection, union and difference; or getting the member with highest ranking in a sorted set.  In order to achieve its outstanding performance, Valkey works with an in-memory dataset. Depending on your use case, you can persist it either by dumping the dataset to disk every once in a while, or by appending each command to a log.  Valkey also supports trivial-to-setup master-slave replication, with very fast non-blocking first synchronization, auto-reconnection on net split and so forth.  Other features include Transactions, Pub/Sub, Lua scripting, Keys with a limited time-to-live, and configuration settings to make Valkey behave like a cache.  You can use Valkey from most programming languages also.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* redis: Redis: Remote Code Execution via specially crafted RESTORE payload (CVE-2026-66373)&lt;/p&gt;
&lt;p&gt;* valkey: Valkey: Remote code execution via use-after-free in stream deserialization (CVE-2026-63639)&lt;/p&gt;
&lt;p&gt;* valkey: Valkey: Remote code execution via TLS pending-data processing use-after-free (CVE-2026-56684)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* [Tracker] Rebase valkey to 8.0.10 (JIRA:Rocky Linux-216776)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:64796</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:3483-1 — Security update for valkey</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:3483-1</link>
      <description>&lt;p&gt;Security update for valkey&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for valkey&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:3483-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-63639</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-63639</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:24.04:LTS: valkey, Ubuntu:26.04:LTS: valkey&lt;/p&gt;
&lt;p&gt;Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey&amp;#39;s RESTORE command accepts a malformed RDB stream payload that assigns one Pending Entry List NACK to multiple consumers during stream consumer-group deserialization, causing a use-after-free when one consumer is deleted while another still references the shared NACK and potentially allowing remote code execution. This issue is fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:24.04:LTS: valkey, Ubuntu:26.04:LTS: valkey&lt;/p&gt;
&lt;p&gt;Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey&amp;#39;s RESTORE command accepts a malformed RDB stream payload that assigns one Pending Entry List NACK to multiple consumers during stream consumer-group deserialization, causing a use-after-free when one consumer is deleted while another still references the shared NACK and potentially allowing remote code execution. This issue is fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-63639</guid>
    </item>
  </channel>
</rss>
