USN-7359-1: Valkey vulnerabilities
19 March 2025
Several security issues were fixed in Valkey.
Releases
Packages
- valkey - Conversion script and compatibility symlinks for Redis
Details
It was discovered that Valkey did not properly handle memory
cleanup. An attacker could possibly use this issue to execute
arbitrary code. (CVE-2024-46981)
It was discovered that Valkey did not properly handle resource
access permissions. An authenticated attacker could possibly
use this issue to cause a denial of service. (CVE-2024-51741)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 24.10
-
valkey-redis-compat
-
7.2.8+dfsg1-0ubuntu0.24.10.2
-
valkey-sentinel
-
7.2.8+dfsg1-0ubuntu0.24.10.2
-
valkey-server
-
7.2.8+dfsg1-0ubuntu0.24.10.2
-
valkey-tools
-
7.2.8+dfsg1-0ubuntu0.24.10.2
Ubuntu 24.04
-
valkey-redis-compat
-
7.2.8+dfsg1-0ubuntu0.24.04.2
-
valkey-sentinel
-
7.2.8+dfsg1-0ubuntu0.24.04.2
-
valkey-server
-
7.2.8+dfsg1-0ubuntu0.24.04.2
-
valkey-tools
-
7.2.8+dfsg1-0ubuntu0.24.04.2
In general, a standard system update will make all the necessary changes.