-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 07 Oct 2025 21:33:04 +0200 Source: valkey Architecture: source Version: 8.1.1+dfsg1-3+deb13u1 Distribution: trixie-security Urgency: medium Maintainer: Lucas Kanashiro <kanashiro@debian.org> Changed-By: Moritz Mühlenhoff <jmm@debian.org> Changes: valkey (8.1.1+dfsg1-3+deb13u1) trixie-security; urgency=medium . * (CVE-2025-49844) A Lua script may lead to remote code execution * (CVE-2025-46817) A Lua script may lead to integer overflow and potential RCE * (CVE-2025-46818) A Lua script can be executed in the context of another user * (CVE-2025-46819) LUA out-of-bound read Checksums-Sha1: 2e28257f7b50aea2f37bb9c9b64edb3c97365f5f 2246 valkey_8.1.1+dfsg1-3+deb13u1.dsc 40f52feab50d74dc579abf6702429bbd080dce39 2726128 valkey_8.1.1+dfsg1.orig.tar.xz f028ec2e8eea23b3ce8a9650bb222be2cf2f4a6b 26804 valkey_8.1.1+dfsg1-3+deb13u1.debian.tar.xz 5d1fdba8e861ce98e46092344505a75fc224c8c6 7609 valkey_8.1.1+dfsg1-3+deb13u1_amd64.buildinfo Checksums-Sha256: 00112b5a7e129c151bb4b23ee37fcfacc2d3d49decdeaae156cf783ade5d2ec0 2246 valkey_8.1.1+dfsg1-3+deb13u1.dsc d9bbd82eecb82f359e649a0007ad3dc1b47cc15afa626348ca86b73c4ae2c7ee 2726128 valkey_8.1.1+dfsg1.orig.tar.xz be6cbd31c98fe2e9eb3b856043577434454a3dd081fd628878047f41000afc09 26804 valkey_8.1.1+dfsg1-3+deb13u1.debian.tar.xz 9914c3412053f7d3ae0aa011da8a9f422ddb8a04e39bd8cda15ec5d968693d3d 7609 valkey_8.1.1+dfsg1-3+deb13u1_amd64.buildinfo Files: 7eadc32c9008c1ec74dcf5d108a22126 2246 database optional valkey_8.1.1+dfsg1-3+deb13u1.dsc 3ec2c18e27d75a0736caa812c2718c41 2726128 database optional valkey_8.1.1+dfsg1.orig.tar.xz 78e1180ab2ff102d0de88461007451d2 26804 database optional valkey_8.1.1+dfsg1-3+deb13u1.debian.tar.xz 2981e72dbf8d47af6787ea332eac71f3 7609 database optional valkey_8.1.1+dfsg1-3+deb13u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmjldAkACgkQEMKTtsN8 TjY8axAAg27Wu+b3tuY42iyYT7aeGtFKF+r4fQ/T7DUB9OMknwPN2b/stpyKss4y 1KOe8p0wreutFPCqqV3cCDQVBB5dmp7KjYL2AwmiBQ2vpXPO6cKojwiFRQSyrkX3 SCHTHRR0KLfy7EIFur12mLT8oi+OxfSe1+IQC6r5v61pOAaOKEc5PSf1omGRDXhH AWn8KNWRuG7NOHvkEtmhiYdDgVFP5NDx3stuLZRCKmJVi08vcEJ3oLikcLxZWAvD w8gbUazLUNvJ+9499haeGaGJrkeqXAN/TV0oT8QHfV4F/Zi7SfHb3OdK/fuc1wOK JlTU1tKXEsZgeBLgJhMHjNWb6GzTcVlbdcjCGQ6QyOdXvrQD3tK2GQuA1Ar3LUEp 8Z7TDaffqquW1Trvzl/Rzb+BlJPqVrcYK57I9iTznMdU7CB3MhYf86DSxQHkcC3B rwfrS3Z2DwiXFz385F+l/x7aNZpErGIHTR5SToKIz2TqURUEFIK8ttI6AcKSDC/s ahZfQqbLBeuQ2hihvB3Tkar08woM4D//8pZz344vv8foziIdcmwpB5paRsbsqPfv 64xMSuo4h90aNZqxxGLAwnYh4SUiDDqr4Yo1cLf+7+KgON+97ny8lCvLmHM7trOv BhjdUikQXyuOTi0nhkKVhBInJWk2A7TOM2nyUhu3udBTstiT3/I= =FVgd -----END PGP SIGNATURE-----