CVE-2026-82677: valkey-io valkey Module Timer module.c moduleTimerHandler double free
A vulnerability was determined in valkey-io valkey 9.1.0. Impacted is the function moduleTimerHandler of the file src/module.c of the component Module Timer Subsystem. This manipulation causes double free. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Patch name: b349fe2821e3998534b1454c1b64a478daf8c6b7. To fix this issue, it is recommended to deploy a patch.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
valkey-io valkeyto a version that resolves this vulnerability.Patch b349fe2821e3998534b1454c1b64a478daf8c6b7
Event History
Frequently Asked Questions
Which deployments are identified as affected?
The affected product and version identified in the data is valkey-io valkey 9.1.0, specifically its Module Timer Subsystem.
What access would an attacker need to exploit this issue?
The issue can be initiated remotely, but the supplied vector indicates that the attacker needs high privileges and user interaction.
What should be done if this version is in use?
Deploy patch b349fe2821e3998534b1454c1b64a478daf8c6b7. A public exploit has been disclosed and may be used.