Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Fedora 40 valkey 8.0.2 critical: remote code execution and DoS threats

fedora
Calendar Grey January 17, 2025
Dist Fedora Esm H88
Fedora 40 valkey 8.0.2 advisory resolves remote code execution and service issues. Ensure your system is secure with updates.
update to 8.0.2 fixes CVE-2024-46981 - Lua script commands may lead to remote code execution fixes CVE-2024-51741 - Denial-of-service due to malformed ACL selectors

Summary

Valkey is an advanced key-value store. It is often referred to as a data

structure server since keys can contain strings, hashes, lists, sets and

sorted sets.

You can run atomic operations on these types, like appending to a string;

incrementing the value in a hash; pushing to a list; computing set

intersection, union and difference; or getting the member with highest

ranking in a sorted set.

In order to achieve its outstanding performance, Valkey works with an

in-memory dataset. Depending on your use case, you can persist it either

by dumping the dataset to disk every once in a while, or by appending

each command to a log.

Valkey also supports trivial-to-setup master-slave replication, with very

fast non-blocking first synchronization, auto-reconnection on net split

and so forth.

Other features include Transactions, Pub/Sub, Lua scripting, Keys with a

limited time-to-live, and configuration settings to make Valkey behave like

a cache.

You can use Valkey from most programming languages also.

Update Information:

update to 8.0.2 fixes CVE-2024-46981 - Lua script commands may lead to remote code execution fixes CVE-2024-51741 - Denial-of-service due to malformed ACL selectors

Change Log

* Wed Jan 8 2025 Jonathan Wright - 8.0.2-1 - update to 8.0.2 rhbz#2336259 fixes CVE-2024-46981 fixes CVE-2024-51741

References

Fedora Update Notification FEDORA-2025-9eccdb2c3e 2025-01-17 01:35:26.873174+00:00 Name : valkey Product : Fedora 40 Version : 8.0.2 Release : 1.fc40 URL : https://valkey.io Summary : A persistent key-value database Description : Valkey is an advanced key-value store. It is often referred to as a data structure server since keys can contain strings, hashes, lists, sets and sorted sets. You can run atomic operations on these types, like appending to a string; incrementing the value in a hash; pushing to a list; computing set intersection, union and difference; or getting the member with highest ranking in a sorted set. In order to achieve its outstanding performance, Valkey works with an in-memory dataset. Depending on your use case, you can persist it either by dumping the dataset to disk every once in a while, or by appending each command to a log. Valkey also supports trivial-to-setup master-slave replication, with very fast non-blocking first synchronization, auto-reconnection on net split and so forth. Other features include Transactions, Pub/Sub, Lua scripting, Keys with a limited time-to-live, and configuration settings to make Valkey behave like a cache. You can use Valkey from most programming languages also.

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-9eccdb2c3e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: valkey
Product: Fedora 40
Version: 8.0.2
Release: 1.fc40
Summary: A persistent key-value database

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here