SUSE-SU-2026:0848-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20260848-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:0848-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:0848-1
Upstream
Related
Published
2026-03-07T18:18:45Z
Modified
2026-03-10T12:45:06.557938Z
Summary
Security update for valkey
Details

This update for valkey fixes the following issues:

Update to version 8.0.7.

Security issues fixed:

  • CVE-2025-67733: data tampering and denial of service via improper null character handling in Lua scripts (bsc#1258746).
  • CVE-2026-21863: denial of service via invalid clusterbus packet (bsc#1258788).

Other updates and bugfixes:

  • ltrim should not call signalModifiedKey when no elements are removed (#2787)
  • chained replica crash when doing dual channel replication (#2983)
  • usedmemorydataset underflow due to miscalculated usedmemoryoverhead (#3005)
  • avoids crash during MODULE UNLOAD when ACL rules reference a module command and subcommand (#3160)
  • server assert on ACL LOAD and resetchannels (#3182)
  • bug causing no response flush sometimes when IO threads are busy (#3205)
References

Affected packages

SUSE:Linux Enterprise Module for Server Applications 15 SP7 / valkey

Package

Name
valkey
Purl
pkg:rpm/suse/valkey&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8.0.7-150700.3.14.1

Ecosystem specific

{
    "binaries": [
        {
            "valkey-devel": "8.0.7-150700.3.14.1",
            "valkey": "8.0.7-150700.3.14.1",
            "valkey-compat-redis": "8.0.7-150700.3.14.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:0848-1.json"