Your message dated Fri, 21 Aug 2026 22:52:02 +0000
with message-id <[email protected]>
and subject line Bug#1144957: fixed in valkey 9.1.1-1
has caused the Debian Bug report #1144957,
regarding valkey: CVE-2026-63639
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1144957: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1144957
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: valkey
Version: 8.1.4+dfsg1-2
Severity: grave
Tags: security upstream
Justification: user security hole
Forwarded: https://github.com/valkey-io/valkey/pull/4073
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for valkey.

CVE-2026-63639[0]:
| Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10,
| 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a
| malformed RDB stream payload that assigns one Pending Entry List
| NACK to multiple consumers during stream consumer-group
| deserialization, causing a use-after-free when one consumer is
| deleted while another still references the shared NACK and
| potentially allowing remote code execution. This issue is fixed in
| versions 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-63639
    https://www.cve.org/CVERecord?id=CVE-2026-63639
[1] https://github.com/valkey-io/valkey/pull/4073
[2] https://github.com/valkey-io/valkey/security/advisories/GHSA-mvcj-73cw-22m4

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: valkey
Source-Version: 9.1.1-1
Done: Lena Voytek <[email protected]>

We believe that the bug you reported is fixed in the latest version of
valkey, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Lena Voytek <[email protected]> (supplier of updated valkey package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Fri, 21 Aug 2026 18:00:08 -0400
Source: valkey
Built-For-Profiles: derivative.ubuntu noudeb
Architecture: source
Version: 9.1.1-1
Distribution: unstable
Urgency: medium
Maintainer: Lucas Kanashiro <[email protected]>
Changed-By: Lena Voytek <[email protected]>
Closes: 1144956 1144957
Changes:
 valkey (9.1.1-1) unstable; urgency=medium
 .
   [ Lena Voytek ]
   * New upstream version 9.1.1 (Closes: #1144957, #1144956).
     - Fix CVE-2026-63639 and CVE-2026-56684.
   * Update patches.
     - Remove d/p/CVE-2025-67733.patch and CVE-2026-21863.patch already applied
       by upstream.
     - Refresh 0002-Add-CPPFLAGS-to-upstream-makefiles.patch.
     - Use defined() instead of == yes for USE_SYSTEM_JEMALLOC in
       0004-Add-support-for-USE_SYSTEM_JEMALLOC-flag.patch.
     - Add 0005-Map-je_posix_memalign-for-system-jemalloc.patch to map
       je_posix_memalign to posix_memalign for system jemalloc.
     - Add 0006-support-openssl4-tlsS-tests.patch to fix TLS unit test failures
       and test certificate generation.
   * Update watch file.
     - Use version 5.
     - Remove repack suffix - no longer needed.
     - Add uversion-mangle to watch for rc versions.
   * Update copyright file for new version.
   * Add Lena Voytek as an uploader.
   * Update standards version and remove unnecessary fields.
   * Remove libhiredis-dev dependency - no longer needed.
 .
   [ Luca Boccassi ]
   * Use sysusers to manage the valkey system user and group.
Checksums-Sha1:
 faec3791c05b11eccce0be72d6a8b740f276e339 2251 valkey_9.1.1-1.dsc
 62a4a1cbe5f25abd644bfd74198469ed68489a80 4392866 valkey_9.1.1.orig.tar.gz
 98aeee2142d449f64b69d1f96e101e85de0bd596 18316 valkey_9.1.1-1.debian.tar.xz
 56fad282d9650642a828ebe2514d13a6151a2c96 8418 valkey_9.1.1-1_source.buildinfo
Checksums-Sha256:
 73a1339f74bd61ec48dc98692ee3344ac45da276e1331dca34b53987bf12ab1c 2251 
valkey_9.1.1-1.dsc
 6ba3d3e775e04cb2a526f20e230104a1974cb1aba17e4ae3b1383e063ee93650 4392866 
valkey_9.1.1.orig.tar.gz
 86a3fe3b5bee990285ebb515d75f439f5dc87b2626ff62cb5c457c42c66a5b8c 18316 
valkey_9.1.1-1.debian.tar.xz
 fed6112279a7819fe29c99928eb59234c8c60f211ccf1866e46f1add34d89307 8418 
valkey_9.1.1-1_source.buildinfo
Files:
 fc97ee260df53c4b39acf7608fe141ea 2251 database optional valkey_9.1.1-1.dsc
 c105d2018a4b42c78c5b588633f01ab0 4392866 database optional 
valkey_9.1.1.orig.tar.gz
 2021896fce9c6404c09cdc3d563a856c 18316 database optional 
valkey_9.1.1-1.debian.tar.xz
 5c42a27fc031a641989d33108f905269 8418 database optional 
valkey_9.1.1-1_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQJEBAEBCgAuFiEEY+78PeFNUUbOfyS/NLitfZUp55MFAmqIzK8QHGxlbmFAZGVi
aWFuLm9yZwAKCRA0uK19lSnnkw0kD/9NV5Lfc9BhQ0vIkX2NvoHiscBVi7K8Irwf
D2wPKZRLoivqSTMUGmuIikHMOLaoxZS5YNq/+Q+q/BRW2lIahroKP1dORTEk1pc0
TsIl/3ViqLQ/jYk6ogaXBUe7zQi464Ptfh/3F7IgOFn7V3gjGsstM78q+DN0AN+E
TTHtYK3YyjP0dvoNoRfb8/mX3y5LM9mHJtZXyl3RmuKNDne3Xe7ApBGx3Vjv7MaX
BgxnV9ynoQCPnjKhppaLy0mnxp53O7BiNC7xIiBpn/4Ob/XiNaiFFEsiKGe0kt9P
UKYWak+8gt0zBDVIG9c2gLV6FnWdAEG3HNCJs626f8LPf91icSvOdrujO8kygu5f
HYpMMC7ybYLjk8vuW4U96fvzheoJQ09dT2Hm8ZfQVGANt4Hm4ij4xCQXJSqvDdWm
UvbP0p4cnBAoEEcPGH29216FGTlaAR6PwupRNBK5q1fDTuKKxTe4JNANg+hFY81g
Pda9HN3xrx8HmW6IwUZBbaNmvHEb8KgJQ53xQY4n91/VPqWXL4pTMgV8XxO1k81+
y1KmhRD27UwCZMa15YeoDsXF+pkJMhg3STVJ6/lQlxvtl3BjKpBjWRK0Cvi5U5sD
dZMejpATkNDsxP6Si2QPlij+YS8v5y+1qSK+LJy25MfT3JlxpIBWY2p7Xwqby9iC
xIaLPDRqJA==
=9SGv
-----END PGP SIGNATURE-----

Attachment: pgpFxqiR9O6eH.pgp
Description: PGP signature


--- End Message ---

Reply via email to