CVE-2025-49112: Integer Underflow
Published Jun 2, 2025
·Updated
setDeferredReply in networking.c in Valkey through 8.1.1 has an integer underflow for prev->size - prev->used.
Affected Software
1 affected component
Valkey Valkey<=8.1.1
Event History
Jun 2, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-49112?
The severity of CVE-2025-49112 is classified as critical due to the potential for integer underflow leading to memory corruption.
2
How do I fix CVE-2025-49112?
To fix CVE-2025-49112, upgrade to Valkey version 8.1.2 or later where the vulnerability has been addressed.
3
What type of vulnerability is CVE-2025-49112?
CVE-2025-49112 is an integer underflow vulnerability found in the setDeferredReply function.
4
Which versions of Valkey are affected by CVE-2025-49112?
Valkey versions up to and including 8.1.1 are affected by CVE-2025-49112.
5
What is the impact of CVE-2025-49112?
The impact of CVE-2025-49112 may include potential exploitation that leads to a denial of service or arbitrary code execution.