[ubuntu/noble-security] valkey 7.2.11+dfsg1-0ubuntu0.2 (Accepted)
Hlib Korzhynskyy
hlib.korzhynskyy at canonical.com
Wed Nov 26 13:30:36 UTC 2025
valkey (7.2.11+dfsg1-0ubuntu0.2) noble-security; urgency=medium
* No change rebuild to copy previous update to the security pocket.
valkey (7.2.11+dfsg1-0ubuntu0.1) noble; urgency=medium
* New upstream version 7.2.11 (LP: #2127122)
- Security fixes:
+ CVE-2025-49844: Lua script may lead to remote code execution.
+ CVE-2025-46817: Lua script may lead to int overflow and potential RCE.
+ CVE-2025-46818: Lua script can be executed in context of another user.
+ CVE-2025-46819: LUA out-of-bound read.
+ CVE-2025-49112: Integer underflow in setDeferredReply networking.c.
- Bug fixes:
+ Ensure empty error tables in scripts don't crash Valkey.
+ Fix client tracking memory overhead calculation.
+ Fix assumptions that pthread functions set errno.
* d/rules: Increase test timeout during build.
valkey (7.2.10+dfsg1-0ubuntu0.1) noble; urgency=medium
* New upstream version 7.2.10 (LP: #2115258)
- Security fixes:
+ CVE-2025-21605: Allocation of Resources Without Limits or Throttling.
+ CVE-2025-32023: Out-of-bounds write during hyperloglog operations.
+ CVE-2025-48367: IP Protocol errors resulting in DoS.
+ CVE-2025-27151: AOF file name length not checked.
- Bug fixes:
+ Only mark the client reprocessing flag when unblocked on keys.
+ Free module context even if there was no content written in auxsave2.
+ Fix Detect SSL_new() returning NULL in outgoing connections.
+ Correctly cast the extension lengths.
+ Fix cluster myself CLUSTER SLOTS/NODES wrong port after updating
port/tls-port.
+ Fix replica can't finish failover when config epoch is outdated.
+ Fix CLIENT UNBLOCK ability to unpause paused clients.
+ Fix defrag crash when using FLUSHDB ASYNC in cluster mode.
+ Fix memory leak in forgotten node ping ext code path.
+ Fix module LatencyAddSample still work when latency-monitor-threshold
is 0.
+ Fix raxRemove crash at memcpy() due to key size exceeds max Rax size.
+ Fix error "SSL routines::bad length" when connTLSWrite is called second
time with smaller buffer.
+ Fix RANDOMKEY infinite loop during CLIENT PAUSE.
+ Fix adding samples to stream object consumer trees.
+ Fix panic in primary when blocking shutdown after previous block with
timeout.
+ Fix incorrect lag reported in XINFO GROUPS.
valkey (7.2.8+dfsg1-0ubuntu0.24.04.3) noble; urgency=medium
* d/valkey-redis-compat.postinst: Do not migrate on upgrade if redis files
have already been migrated (LP: #2104217).
Date: 2025-11-19 17:53:17.114543+00:00
Changed-By: Hlib Korzhynskyy <hlib.korzhynskyy at canonical.com>
https://launchpad.net/ubuntu/+source/valkey/7.2.11+dfsg1-0ubuntu0.2
-------------- next part --------------
Sorry, changesfile not available.
More information about the noble-changes
mailing list