Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:26540 - Security Advisory
Issued:
2026-06-17
Updated:
2026-06-17

RHSA-2026:26540 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: valkey security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for valkey is now available for Red Hat Enterprise Linux 10.0 Extended Update Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Valkey is an advanced key-value store. It is often referred to as a data structure server since keys can contain strings, hashes, lists, sets and sorted sets. You can run atomic operations on these types, like appending to a string; incrementing the value in a hash; pushing to a list; computing set intersection, union and difference; or getting the member with highest ranking in a sorted set. In order to achieve its outstanding performance, Valkey works with an in-memory dataset. Depending on your use case, you can persist it either by dumping the dataset to disk every once in a while, or by appending each command to a log. Valkey also supports trivial-to-setup master-slave replication, with very fast non-blocking first synchronization, auto-reconnection on net split and so forth. Other features include Transactions, Pub/Sub, Lua scripting, Keys with a limited time-to-live, and configuration settings to make Valkey behave like a cache. You can use Valkey from most programming languages also.

Security Fix(es):

  • redis: use-after-free in unblock client flow may allow remote code execution (CVE-2026-23479)
  • redis: Remote code execution via use-after-free in Lua scripting (CVE-2026-23631)
  • redis: RESTORE invalid memory access may allow remote code execution (CVE-2026-25243)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 x86_64
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 s390x
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 ppc64le
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 aarch64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0 s390x
  • Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0 x86_64

Fixes

  • BZ - 2466780 - CVE-2026-23479 redis: use-after-free in unblock client flow may allow remote code execution
  • BZ - 2466788 - CVE-2026-23631 redis: Remote code execution via use-after-free in Lua scripting
  • BZ - 2466828 - CVE-2026-25243 redis: RESTORE invalid memory access may allow remote code execution

CVEs

  • CVE-2026-23479
  • CVE-2026-23631
  • CVE-2026-25243

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0

SRPM
valkey-8.0.9-1.el10_0.src.rpm SHA-256: f8c3760098e975144c6b556a2b9071053d5833e8ba53cced381281461a00ede0
x86_64
valkey-8.0.9-1.el10_0.x86_64.rpm SHA-256: a9273a7a276f75d9c1851789739a2ecc79f6fbb2755c19732ffa73a3edae5676
valkey-debuginfo-8.0.9-1.el10_0.x86_64.rpm SHA-256: c9c5fbf3ae92c0e380f26a84acddfc74d57b86fe0e3a310b47223bc373bb7fb7
valkey-debugsource-8.0.9-1.el10_0.x86_64.rpm SHA-256: 5e9c9a9b39bbbda9867e507d6955a642dc17ecd2e0b6d93047189a04a6e68015
valkey-devel-8.0.9-1.el10_0.x86_64.rpm SHA-256: 334f72d2960ad0648e071603ccee81b312197de4c3b8ef86d5517a8b43bb5d0d

Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0

SRPM
valkey-8.0.9-1.el10_0.src.rpm SHA-256: f8c3760098e975144c6b556a2b9071053d5833e8ba53cced381281461a00ede0
s390x
valkey-8.0.9-1.el10_0.s390x.rpm SHA-256: 0a7c512f6df69c00aef5a4823834a9e2087c1f375ad9854eb10c10808ccec215
valkey-debuginfo-8.0.9-1.el10_0.s390x.rpm SHA-256: 1f78d840fc82f41a0d9c3640f7aa507f5df01ece54f4a2f52cc60427c3c08da9
valkey-debugsource-8.0.9-1.el10_0.s390x.rpm SHA-256: aa5cb9616a9edbcdd4cdea4fa87214b0edb70df8400935ab0c540943248ada22
valkey-devel-8.0.9-1.el10_0.s390x.rpm SHA-256: b74ccbd8ab10817b41206c20ec1575f57298544c65104e3f7faf2111027091f0

Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0

SRPM
valkey-8.0.9-1.el10_0.src.rpm SHA-256: f8c3760098e975144c6b556a2b9071053d5833e8ba53cced381281461a00ede0
ppc64le
valkey-8.0.9-1.el10_0.ppc64le.rpm SHA-256: d77ab43067eddf307c648e8fa6daaaf5e0fbacaa80f131d65ba28edf46156ab7
valkey-debuginfo-8.0.9-1.el10_0.ppc64le.rpm SHA-256: f0ea28ed0c53aa5eb0f0f03bcc30f559b99f218b23b55e0263a9f01732532526
valkey-debugsource-8.0.9-1.el10_0.ppc64le.rpm SHA-256: dc6cef2082685367ef5ce1c5b8772e9831c2a91811fdfef01c36028100669d1b
valkey-devel-8.0.9-1.el10_0.ppc64le.rpm SHA-256: 94c7a96f7bbb05c245623321a39653a337daa3add487a5107c249082872c1875

Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0

SRPM
valkey-8.0.9-1.el10_0.src.rpm SHA-256: f8c3760098e975144c6b556a2b9071053d5833e8ba53cced381281461a00ede0
aarch64
valkey-8.0.9-1.el10_0.aarch64.rpm SHA-256: aa0caa47f0e154df8f48ab5118bd2f964cc734c0d06e9e64597a1bb13d9fa077
valkey-debuginfo-8.0.9-1.el10_0.aarch64.rpm SHA-256: e78249f5063b1e4f45d2b5b63ba01a21bf1d5cfc2a5a14a64646d0a3c5e99852
valkey-debugsource-8.0.9-1.el10_0.aarch64.rpm SHA-256: c40f98d712effb9ff3348d1ff73f55e78e78e4ec0790268f105f1d237c9a8f1a
valkey-devel-8.0.9-1.el10_0.aarch64.rpm SHA-256: 049749a11d5c7c6ad4c62fe11e5e0c7ade7aef8052dbfd4f2ea5dbe75f87725b

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0

SRPM
valkey-8.0.9-1.el10_0.src.rpm SHA-256: f8c3760098e975144c6b556a2b9071053d5833e8ba53cced381281461a00ede0
aarch64
valkey-8.0.9-1.el10_0.aarch64.rpm SHA-256: aa0caa47f0e154df8f48ab5118bd2f964cc734c0d06e9e64597a1bb13d9fa077
valkey-debuginfo-8.0.9-1.el10_0.aarch64.rpm SHA-256: e78249f5063b1e4f45d2b5b63ba01a21bf1d5cfc2a5a14a64646d0a3c5e99852
valkey-debugsource-8.0.9-1.el10_0.aarch64.rpm SHA-256: c40f98d712effb9ff3348d1ff73f55e78e78e4ec0790268f105f1d237c9a8f1a
valkey-devel-8.0.9-1.el10_0.aarch64.rpm SHA-256: 049749a11d5c7c6ad4c62fe11e5e0c7ade7aef8052dbfd4f2ea5dbe75f87725b

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0

SRPM
valkey-8.0.9-1.el10_0.src.rpm SHA-256: f8c3760098e975144c6b556a2b9071053d5833e8ba53cced381281461a00ede0
s390x
valkey-8.0.9-1.el10_0.s390x.rpm SHA-256: 0a7c512f6df69c00aef5a4823834a9e2087c1f375ad9854eb10c10808ccec215
valkey-debuginfo-8.0.9-1.el10_0.s390x.rpm SHA-256: 1f78d840fc82f41a0d9c3640f7aa507f5df01ece54f4a2f52cc60427c3c08da9
valkey-debugsource-8.0.9-1.el10_0.s390x.rpm SHA-256: aa5cb9616a9edbcdd4cdea4fa87214b0edb70df8400935ab0c540943248ada22
valkey-devel-8.0.9-1.el10_0.s390x.rpm SHA-256: b74ccbd8ab10817b41206c20ec1575f57298544c65104e3f7faf2111027091f0

Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0

SRPM
valkey-8.0.9-1.el10_0.src.rpm SHA-256: f8c3760098e975144c6b556a2b9071053d5833e8ba53cced381281461a00ede0
ppc64le
valkey-8.0.9-1.el10_0.ppc64le.rpm SHA-256: d77ab43067eddf307c648e8fa6daaaf5e0fbacaa80f131d65ba28edf46156ab7
valkey-debuginfo-8.0.9-1.el10_0.ppc64le.rpm SHA-256: f0ea28ed0c53aa5eb0f0f03bcc30f559b99f218b23b55e0263a9f01732532526
valkey-debugsource-8.0.9-1.el10_0.ppc64le.rpm SHA-256: dc6cef2082685367ef5ce1c5b8772e9831c2a91811fdfef01c36028100669d1b
valkey-devel-8.0.9-1.el10_0.ppc64le.rpm SHA-256: 94c7a96f7bbb05c245623321a39653a337daa3add487a5107c249082872c1875

Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0

SRPM
valkey-8.0.9-1.el10_0.src.rpm SHA-256: f8c3760098e975144c6b556a2b9071053d5833e8ba53cced381281461a00ede0
x86_64
valkey-8.0.9-1.el10_0.x86_64.rpm SHA-256: a9273a7a276f75d9c1851789739a2ecc79f6fbb2755c19732ffa73a3edae5676
valkey-debuginfo-8.0.9-1.el10_0.x86_64.rpm SHA-256: c9c5fbf3ae92c0e380f26a84acddfc74d57b86fe0e3a310b47223bc373bb7fb7
valkey-debugsource-8.0.9-1.el10_0.x86_64.rpm SHA-256: 5e9c9a9b39bbbda9867e507d6955a642dc17ecd2e0b6d93047189a04a6e68015
valkey-devel-8.0.9-1.el10_0.x86_64.rpm SHA-256: 334f72d2960ad0648e071603ccee81b312197de4c3b8ef86d5517a8b43bb5d0d

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility