CVE-2026-56684

EUVD-2026-60822
Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's tlsProcessPendingData function iterates pending_list while an authenticated client can trigger CLIENT KILL, causing connTLSClose to delete the iterator's cached next node and producing a use-after-free that can crash the server or potentially allow remote code execution when TLS is enabled. This issue is fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
valkey
suse enterprise sap 15 SP7
8.0.10-150700.3.20.1
fixed
suse enterprise server 15 SP6
8.0.10-150600.13.28.1
fixed
suse enterprise server 15 SP7
8.0.10-150700.3.20.1
fixed
valkey-compat-redis
suse enterprise sap 15 SP7
8.0.10-150700.3.20.1
fixed
suse enterprise server 15 SP6
8.0.10-150600.13.28.1
fixed
suse enterprise server 15 SP7
8.0.10-150700.3.20.1
fixed
valkey-devel
suse enterprise sap 15 SP7
8.0.10-150700.3.20.1
fixed
suse enterprise server 15 SP6
8.0.10-150600.13.28.1
fixed
suse enterprise server 15 SP7
8.0.10-150700.3.20.1
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
valkey
Amazon Linux 2023
0:9.0.5-1.amzn2023.0.1
fixed
valkey-debuginfo
Amazon Linux 2023
0:9.0.5-1.amzn2023.0.1
fixed
valkey-debugsource
Amazon Linux 2023
0:9.0.5-1.amzn2023.0.1
fixed
valkey-devel
Amazon Linux 2023
0:9.0.5-1.amzn2023.0.1
fixed