Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 14

Количество 14

ubuntu логотип

CVE-2026-21863

5 месяцев назад

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious actor with access to the Valkey clusterbus port can send an invalid packet that may cause an out bound read, which might result in the system crashing. The Valkey clusterbus packet processing code does not validate that a clusterbus ping extension packet is located within buffer of the clusterbus packet before attempting to read it. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue. As an additional mitigation, don't expose the cluster bus connection directly to end users, and protect the connection with its own network ACLs.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-21863

5 месяцев назад

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious actor with access to the Valkey clusterbus port can send an invalid packet that may cause an out bound read, which might result in the system crashing. The Valkey clusterbus packet processing code does not validate that a clusterbus ping extension packet is located within buffer of the clusterbus packet before attempting to read it. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue. As an additional mitigation, don't expose the cluster bus connection directly to end users, and protect the connection with its own network ACLs.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-21863

5 месяцев назад

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious actor with access to the Valkey clusterbus port can send an invalid packet that may cause an out bound read, which might result in the system crashing. The Valkey clusterbus packet processing code does not validate that a clusterbus ping extension packet is located within buffer of the clusterbus packet before attempting to read it. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue. As an additional mitigation, don't expose the cluster bus connection directly to end users, and protect the connection with its own network ACLs.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2026-21863

5 месяцев назад

Malformed Valkey Cluster bus message can lead to Remote DoS

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-21863

5 месяцев назад

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8 ...

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2026-07339

5 месяцев назад

Уязвимость сервера структур данных Valkey, связанная с чтением за границами буфера в памяти, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0848-1

5 месяцев назад

Security update for valkey

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0685-1

5 месяцев назад

Security update for valkey

EPSS: Низкий
redos логотип

ROS-20260430-73-0002

3 месяца назад

Уязвимость valkey

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2026:3507

5 месяцев назад

Important: valkey security update

EPSS: Низкий
rocky логотип

RLSA-2026:3443

5 месяцев назад

Important: valkey security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-3507

5 месяцев назад

ELSA-2026-3507: valkey security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-3443

5 месяцев назад

ELSA-2026-3443: valkey security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20776-1

2 месяца назад

Security update for valkey

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-21863

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious actor with access to the Valkey clusterbus port can send an invalid packet that may cause an out bound read, which might result in the system crashing. The Valkey clusterbus packet processing code does not validate that a clusterbus ping extension packet is located within buffer of the clusterbus packet before attempting to read it. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue. As an additional mitigation, don't expose the cluster bus connection directly to end users, and protect the connection with its own network ACLs.

CVSS3: 7.5
1%
Низкий
5 месяцев назад
redhat логотип
CVE-2026-21863

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious actor with access to the Valkey clusterbus port can send an invalid packet that may cause an out bound read, which might result in the system crashing. The Valkey clusterbus packet processing code does not validate that a clusterbus ping extension packet is located within buffer of the clusterbus packet before attempting to read it. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue. As an additional mitigation, don't expose the cluster bus connection directly to end users, and protect the connection with its own network ACLs.

CVSS3: 7.5
1%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-21863

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12, a malicious actor with access to the Valkey clusterbus port can send an invalid packet that may cause an out bound read, which might result in the system crashing. The Valkey clusterbus packet processing code does not validate that a clusterbus ping extension packet is located within buffer of the clusterbus packet before attempting to read it. Versions 9.0.2, 8.1.6, 8.0.7, and 7.2.12 fix the issue. As an additional mitigation, don't expose the cluster bus connection directly to end users, and protect the connection with its own network ACLs.

CVSS3: 7.5
1%
Низкий
5 месяцев назад
msrc логотип
CVE-2026-21863

Malformed Valkey Cluster bus message can lead to Remote DoS

CVSS3: 7.5
1%
Низкий
5 месяцев назад
debian логотип
CVE-2026-21863

Valkey is a distributed key-value database. Prior to versions 9.0.2, 8 ...

CVSS3: 7.5
1%
Низкий
5 месяцев назад
fstec логотип
BDU:2026-07339

Уязвимость сервера структур данных Valkey, связанная с чтением за границами буфера в памяти, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
1%
Низкий
5 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0848-1

Security update for valkey

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0685-1

Security update for valkey

5 месяцев назад
redos логотип
ROS-20260430-73-0002

Уязвимость valkey

CVSS3: 7.5
1%
Низкий
3 месяца назад
rocky логотип
RLSA-2026:3507

Important: valkey security update

5 месяцев назад
rocky логотип
RLSA-2026:3443

Important: valkey security update

5 месяцев назад
oracle-oval логотип
ELSA-2026-3507

ELSA-2026-3507: valkey security update (IMPORTANT)

5 месяцев назад
oracle-oval логотип
ELSA-2026-3443

ELSA-2026-3443: valkey security update (IMPORTANT)

5 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20776-1

Security update for valkey

2 месяца назад

Уязвимостей на страницу