USN-8771-1: Valkey vulnerabilities
Ubuntu issued USN-8771-1 fixing Valkey flaws (CVE-2026-56684, CVE-2026-63639) that allow denial of service or possible code execution.
Ubuntu Security Notice USN-8771-1 patches multiple vulnerabilities in Valkey, the Redis-compatible in-memory data store. CVE-2026-56684, discovered by Madelyn Olson, involves incorrect TLS connection handling that a remote attacker could trigger to crash Valkey or possibly execute arbitrary code. CVE-2026-63639 involves incorrect handling of stream RDB payloads via the RESTORE command, exploitable by an authenticated remote attacker for denial of service or possible code execution. A third flaw in cluster slot migration operations also allows remote attackers to crash the service.
28