Impact
A memory corruption flaw exists in the handleClientsBlockedOnKey function of Valkey 9.1.0. The use‑after‑free vulnerability can be triggered remotely and may allow an attacker to corrupt the process memory, potentially leading to arbitrary code execution or denial‑of‑service. The description indicates high complexity and a difficult exploit, yet an exploit has been released publicly. The CVSS score of 2.1 reflects that the impact is considered low by the assessor, but the public availability of the exploit requires attention.
Affected Systems
The flaw affects valkey-io’s Valkey 9.1.0 release. No other releases have been confirmed as vulnerable at this time. The issue resides in the Blocked‑on‑keys subsystem within src/blocked.c.
Risk and Exploitability
The vulnerability has a low CVSS score of 2.1, an unavailable EPSS score, and is not listed in the CISA KEV catalog, suggesting a modest exploitation probability. The attack vector is limited to remote connections to the Valkey instance, and the exploit is considered difficult but feasible with the published PoC. Because the flaw allows potential memory corruption, the overall risk warrants immediate correction before attackers can mount a successful exploitation.
OpenCVE Enrichment