Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:26540: Important: valkey security update

This security update addresses three critical vulnerabilities in Valkey (a Redis fork) that enable remote code execution via use-after-free flaws in the client unblock flow, Lua scripting, and the RESTORE command. The CVSS scores for these vulnerabilities are high, ranging from 8.1 to 8.8. Affected versions include Redis (the upstream project) versions prior to 8.6.3, specifically from 7.2.0 to below 8.6.3 for CVE-2026-23479 and all versions below 8.6.3 for the other CVEs; the fixed version is 8.6.3.
Read Full Article →

Red Hat Product Errata RHSA-2026:26540 - Security Advisory Issued: 2026-06-17 Updated: 2026-06-17 RHSA-2026:26540 - Security Advisory Overview Updated Packages Synopsis Important: valkey security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for valkey is now available for Red Hat Enterprise Linux 10.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Valkey is an advanced key-value store. It is often referred to as a data structure server since keys can contain strings, hashes, lists, sets and sorted sets. You can run atomic operations on these types, like appending to a string; incrementing the value in a hash; pushing to a list; computing set intersection, union and difference; or getting the member with highest ranking in a sorted set. In order to achieve its outstanding performance, Valkey works with an in-memory dataset. Depending on your use case, you can persist it either by dumping the dataset to disk every once in a while, or by appending each command to a log. Valkey also supports trivial-to-setup master-slave replication, with very fast non-blocking first synchronization, auto-reconnection on net split and so forth. Other features include Transactions, Pub/Sub, Lua scripting, Keys with a limited time-to-live, and configuration settings to make Valkey behave like a cache. You can use Valkey from most programming languages also. Security Fix(es): redis: use-after-free in unblock client flow may allow remote code execution (CVE-2026-23479) redis: Remote code execution via use-after-free in Lua scripting (CVE-2026-23631) redis: RESTORE invalid memory access may allow remote code execution (CVE-2026-25243) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0 x86_64 Fixes BZ - 2466780 - CVE-2026-23479 redis: use-after-free in unblock client flow may allow remote code execution BZ - 2466788 - CVE-2026-23631 redis: Remote code execution via use-after-free in Lua scripting BZ - 2466828 - CVE-2026-25243 redis: RESTORE invalid memory access may allow remote code execution CVEs CVE-2026-23479 CVE-2026-23631 CVE-2026-25243 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 SRPM valkey-8.0.9-1.el10_0.src.rpm SHA-256: f8c3760098e975144c6b556a2b9071053d5833e8ba53cced381281461a00ede0 x86_64 valkey-8.0.9-1.el10_0.x86_64.rpm SHA-256: a9273a7a276f75d9c1851789739a2ecc79f6fbb2755c19732ffa73a3edae5676 valkey-debuginfo-8.0.9-1.el10_0.x86_64.rpm SHA-256: c9c5fbf3ae92c0e380f26a84acddfc74d57b86fe0e3a310b47223bc373bb7fb7 valkey-debugsource-8.0.9-1.el10_0.x86_64.rpm SHA-256: 5e9c9a9b39bbbda9867e507d6955a642dc17ecd2e0b6d93047189a04a6e68015 valkey-devel-8.0.9-1.el10_0.x86_64.rpm SHA-256: 334f72d2960ad0648e071603ccee81b312197de4c3b8ef86d5517a8b43bb5d0d Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 SRPM valkey-8.0.9-1.el10_0.src.rpm SHA-256: f8c3760098e975144c6b556a2b9071053d5833e8ba53cced381281461a00ede0 s390x valkey-8.0.9-1.el10_0.s390x.rpm SHA-256: 0a7c512f6df69c00aef5a4823834a9e2087c1f375ad9854eb10c10808ccec215 valkey-debuginfo-8.0.9-1.el10_0.s390x.rpm SHA-256: 1f78d840fc82f41a0d9c3640f7aa507f5df01ece54f4a2f52cc60427c3c08da9 valkey-debugsource-8.0.9-1.el10_0.s390x.rpm SHA-256: aa5cb9616a9edbcdd4cdea4fa87214b0edb70df8400935ab0c540943248ada22 valkey-devel-8.0.9-1.el10_0.s390x.rpm SHA-256: b74ccbd8ab10817b41206c20ec1575f57298544c65104e3f7faf2111027091f0 Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 SRPM valkey-8.0.9-1.el10_0.src.rpm SHA-256: f8c3760098e975144c6b556a2b9071053d5833e8ba53cced381281461a00ede0 ppc64le valkey-8.0.9-1.el10_0.ppc64le.rpm SHA-256: d77ab43067eddf307c648e8fa6daaaf5e0fbacaa80f131d65ba28edf46156ab7 valkey-debuginfo-8.0.9-1.el10_0.ppc64le.rpm SHA-256: f0ea28ed0c53aa5eb0f0f03bcc30f559b99f218b23b55e0263a9f01732532526 valkey-debugsource-8.0.9-1.el10_0.ppc64le.rpm SHA-256: dc6cef2082685367ef5ce1c5b8772e9831c2a91811fdfef01c36028100669d1b valkey-devel-8.0.9-1.el10_0.ppc64le.rpm SHA-256: 94c7a96f7bbb05c245623321a39653a337daa3add487a5107c249082872c1875 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 SRPM valkey-8.0.9-1.el10_0.src.rpm SHA-256: f8c3760098e975144c6b556a2b9071053d5833e8ba53cced381281461a00ede0 aarch64 valkey-8.0.9-1.el10_0.aarch64.rpm SHA-256: aa0caa47f0e154df8f48ab5118bd2f964cc734c0d06e9e64597a1bb13d9fa077 valkey-debuginfo-8.0.9-1.el10_0.aarch64.rpm SHA-256: e78249f5063b1e4f45d2b5b63ba01a21bf1d5cfc2a5a14a64646d0a3c5e99852 valkey-debugsource-8.0.9-1.el10_0.aarch64.rpm SHA-256: c40f98d712effb9ff3348d1ff73f55e78e78e4ec0790268f105f1d237c9a8f1a valkey-devel-8.0.9-1.el10_0.aarch64.rpm SHA-256: 049749a11d5c7c6ad4c62fe11e5e0c7ade7aef8052dbfd4f2ea5dbe75f87725b Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 SRPM valkey-8.0.9-1.el10_0.src.rpm SHA-256: f8c3760098e975144c6b556a2b9071053d5833e8ba53cced381281461a00ede0 aarch64 valkey-8.0.9-1.el10_0.aarch64.rpm SHA-256: aa0caa47f0e154df8f48ab5118bd2f964cc734c0d06e9e64597a1bb13d9fa077 valkey-debuginfo-8.0.9-1.el10_0.aarch64.rpm SHA-256: e78249f5063b1e4f45d2b5b63ba01a21bf1d5cfc2a5a14a64646d0a3c5e99852 valkey-debugsource-8.0.9-1.el10_0.aarch64.rpm SHA-256: c40f98d712effb9ff3348d1ff73f55e78e78e4ec0790268f105f1d237c9a8f1a valkey-devel-8.0.9-1.el10_0.aarch64.rpm SHA-256: 049749a11d5c7c6ad4c62fe11e5e0c7ade7aef8052dbfd4f2ea5dbe75f87725b Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0 SRPM valkey-8.0.9-1.el10_0.src.rpm SHA-256: f8c3760098e975144c6b556a2b9071053d5833e8ba53cced381281461a00ede0 s390x valkey-8.0.9-1.el10_0.s390x.rpm SHA-256: 0a7c512f6df69c00aef5a4823834a9e2087c1f375ad9854eb10c10808ccec215 valkey-debuginfo-8.0.9-1.el10_0.s390x.rpm SHA-256: 1f78d840fc82f41a0d9c3640f7aa507f5df01ece54f4a2f52cc60427c3c08da9 valkey-debugsource-8.0.9-1.el10_0.s390x.rpm SHA-256: aa5cb9616a9edbcdd4cdea4fa87214b0edb70df8400935ab0c540943248ada22 valkey-devel-8.0.9-1.el10_0.s390x.rpm SHA-256: b74ccbd8ab10817b41206c20ec1575f57298544c65104e3f7faf2111027091f0 Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0 SRPM valkey-8.0.9-1.el10_0.src.rpm SHA-256: f8c3760098e975144c6b556a2b9071053d5833e8ba53cced381281461a00ede0 ppc64le valkey-8.0.9-1.el10_0.ppc64le.rpm SHA-256: d77ab43067eddf307c648e8fa6daaaf5e0fbacaa80f131d65ba28edf46156ab7 valkey-debuginfo-8.0.9-1.el10_0.ppc64le.rpm SHA-256: f0ea28ed0c53aa5eb0f0f03bcc30f559b99f218b23b55e0263a9f01732532526 valkey-debugsource-8.0.9-1.el10_0.ppc64le.rpm SHA-256: dc6cef2082685367ef5ce1c5b8772e9831c2a91811fdfef01c36028100669d1b valkey-devel-8.0.9-1.el10_0.ppc64le.rpm SHA-256: 94c7a96f7bbb05c245623321a39653a337daa3add487a5107c249082872c1875 Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0 SRPM valkey-8.0.9-1.el10_0.src.rpm SHA-256: f8c3760098e975144c6b556a2b9071053d5833e8ba53cced381281461a00ede0 x86_64 valkey-8.0.9-1.el10_0.x86_64.rpm SHA-256: a9273a7a276f75d9c1851789739a2ecc79f6fbb2755c19732ffa73a3edae5676 valkey-debuginfo-8.0.9-1.el10_0.x86_64.rpm SHA-256: c9c5fbf3ae92c0e380f26a84acddfc74d57b86fe0e3a310b47223bc373bb7fb7 valkey-debugsource-8.0.9-1.el10_0.x86_64.rpm SHA-256: 5e9c9a9b39bbbda9867e507d6955a642dc17ecd2e0b6d93047189a04a6e68015 valkey-devel-8.0.9-1.el10_0.x86_64.rpm SHA-256: 334f72d2960ad0648e071603ccee81b312197de4c3b8ef86d5517a8b43bb5d0d The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .

Share this article