CVE-2026-63639

EUVD-2026-60823
Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed RDB stream payload that assigns one Pending Entry List NACK to multiple consumers during stream consumer-group deserialization, causing a use-after-free when one consumer is deleted while another still references the shared NACK and potentially allowing remote code execution. This issue is fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
valkey
suse enterprise sap 15 SP7
8.0.10-150700.3.20.1
fixed
suse enterprise server 15 SP6
8.0.10-150600.13.28.1
fixed
suse enterprise server 15 SP7
8.0.10-150700.3.20.1
fixed
valkey-compat-redis
suse enterprise sap 15 SP7
8.0.10-150700.3.20.1
fixed
suse enterprise server 15 SP6
8.0.10-150600.13.28.1
fixed
suse enterprise server 15 SP7
8.0.10-150700.3.20.1
fixed
valkey-devel
suse enterprise sap 15 SP7
8.0.10-150700.3.20.1
fixed
suse enterprise server 15 SP6
8.0.10-150600.13.28.1
fixed
suse enterprise server 15 SP7
8.0.10-150700.3.20.1
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
valkey
Amazon Linux 2023
0:9.0.5-1.amzn2023.0.1
fixed
valkey-debuginfo
Amazon Linux 2023
0:9.0.5-1.amzn2023.0.1
fixed
valkey-debugsource
Amazon Linux 2023
0:9.0.5-1.amzn2023.0.1
fixed
valkey-devel
Amazon Linux 2023
0:9.0.5-1.amzn2023.0.1
fixed