REDHAT-BUG-2442026: High severity Valkey Valkey vulnerability
Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious actor with access to the Valkey clusterbus port can send an invalid packet that may cause an out bound read, which might result in the system crashing. The Valkey clusterbus packet processing code does not validate that a clusterbus ping extension packet is located within buffer of the clusterbus packet before attempting to read it. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue. As an additional mitigation, don't expose the cluster bus connection directly to end users, and protect the connection with its own network ACLs.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.0.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.1.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.0.7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.2.12 - Compensating control
Do not expose the Valkey cluster bus connection directly to end users; protect the cluster bus connection with its own network ACLs.
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2442026?
REDHAT-BUG-2442026 has a critical severity level due to the potential for a malicious actor to crash the Valkey system.
How do I fix REDHAT-BUG-2442026?
To fix REDHAT-BUG-2442026, upgrade to Valkey versions 9.0.2, 8.1.6, 8.0.7, or 7.2.12 or later.
What versions of Valkey are affected by REDHAT-BUG-2442026?
Valkey versions prior to 9.0.2, 8.1.6, 8.0.7, and 7.2.12 are affected by REDHAT-BUG-2442026.
What type of attack is described in REDHAT-BUG-2442026?
REDHAT-BUG-2442026 describes an attack where a malicious actor sends an invalid packet through the Valkey clusterbus port.
Can REDHAT-BUG-2442026 lead to data loss?
Yes, if exploited, REDHAT-BUG-2442026 may result in system crashes that could lead to potential data loss.