Impact
The vulnerability is a double free condition in the moduleTimerHandler function of Valkey’s Module Timer subsystem, triggered in the 9.1.0 release. The description states that the flaw can be initiated remotely and that an exploit has been publicly disclosed. When executed, the double free leads to undefined behavior that could manifest as application crash or, potentially, arbitrary code execution, as the memory management after a timer event is improperly handled.
Affected Systems
Valkey-io Valkey version 9.1.0 is affected. No other versions are listed, and the patch that resolves the flaw corresponds to commit b349fe2821e3998534b1454c1b64a478daf8c6b7 on the project’s GitHub repository.
Risk and Exploitability
The vulnerability carries a CVSS score of 4.8, indicating moderate severity. The EPSS score of less than 1% shows a very low exploitation probability. The flaw is not catalogued in CISA’s KEV list. The attack can be initiated remotely; based on the description, it is inferred that the attacker must leverage exposed interfaces of the Module Timer subsystem to trigger moduleTimerHandler. Once triggered, the double free could compromise availability or, with additional conditions, lead to arbitrary code execution.
OpenCVE Enrichment