stable

valkey-9.0.3-1.fc44

FEDORA-2026-ca1077dd2e created by remi 6 months ago for Fedora 44

Valkey 9.0.3 - February 23, 2026

Upgrade urgency SECURITY: This release includes security fixes we recommend you apply as soon as possible.

Security fixes

  • (CVE-2025-67733) RESP Protocol Injection via Lua error_reply
  • (CVE-2026-21863) Remote DoS with malformed Valkey Cluster bus message
  • (CVE-2026-27623) Reset request type after handling empty requests

Bug fixes

  • Avoids crash during MODULE UNLOAD when ACL rules reference a module command and subcommand (#3160)
  • Fix server assert on ACL LOAD when current user loses permission to channels (#3182)
  • Fix bug causing no response flush sometimes when IO threads are busy (#3205)

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2026-ca1077dd2e

This update has been submitted for testing by remi.

6 months ago

This update's test gating status has been changed to 'ignored'.

6 months ago

This update has been pushed to testing.

6 months ago

This update has been submitted for stable by bodhi.

There is an ongoing freeze; this will be pushed to stable after the freeze is over.

5 months ago

This update has been pushed to stable.

5 months ago

Please log in to add feedback.

Metadata
Type
security
Severity
high
Karma
0
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
7 days
Dates
submitted
6 months ago
in testing
6 months ago
in stable
5 months ago
approved
5 months ago
BZ#2442220 CVE-2025-67733 valkey: Valkey: Data tampering and denial of service via improper null character handling in Lua scripts [fedora-all]
0
0
BZ#2442222 CVE-2026-27623 valkey: Valkey: Denial of Service via specially crafted network requests [fedora-all]
0
0
BZ#2442231 CVE-2026-21863 valkey: Valkey: Denial of Service via invalid clusterbus packet [fedora-all]
0
0

Automated Test Results