CVE-2026-21863
EUVD-2026-751323.02.2026, 20:28
Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious actor with access to the Valkey clusterbus port can send an invalid packet that may cause an out bound read, which might result in the system crashing. The Valkey clusterbus packet processing code does not validate that a clusterbus ping extension packet is located within buffer of the clusterbus packet before attempting to read it. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue. As an additional mitigation, don't expose the cluster bus connection directly to end users, and protect the connection with its own network ACLs.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| lfprojects | valkey | 𝑥 < 7.2.12 |
| lfprojects | valkey | 8.0.0 ≤ 𝑥 < 8.0.7 |
| lfprojects | valkey | 8.1.0 ≤ 𝑥 < 8.1.6 |
| lfprojects | valkey | 9.0.0 ≤ 𝑥 < 9.0.2 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | 0:8.0.7-1.el10_1 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | 0:8.0.7-1.el10_0 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9 | 0:8.0.7-1.el9_7 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Hardened Images | 9.0.3-1.2.hum1 ≤ 𝑥 < * | ADP |
Debian Releases
Debian Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| redict |
| ||||||||||||||||
| redis |
| ||||||||||||||||
| valkey |
|
Ubuntu Releases
Red Hat Enterprise Linux Releases
Amazon Linux Releases
Common Weakness Enumeration
References