Executive brief
Valkey is a distributed key-value database used to cache and store data in production systems. A flaw in how Valkey processes the RESTORE command can cause the application to crash or potentially execute arbitrary code when a specially crafted database snapshot is loaded. An attacker with network access to a Valkey instance could trigger this vulnerability to disrupt service or gain control of the database server.
Technical details
The vulnerability is a use-after-free in Valkey's RDB stream consumer-group deserialization logic. When the RESTORE command processes a malformed RDB payload, it can create a situation where a single Pending Entry List (NACK) is assigned to multiple consumers without validation. When one consumer is later deleted, the shared NACK is freed but another consumer still holds a reference to it, causing a use-after-free condition. This flaw requires sending a specially crafted RDB stream payload to the RESTORE command and can allow remote code execution. The vulnerability is fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1 by adding validation to reject corrupt RDB payloads where a NACK is assigned to multiple consumers.
Affected products
- Valkey Valkey prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1
Timeline
- 2026-08-18: disclosed
- 2026-08-18: patched: Fixed in versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1