Impact
A buffer-related flaw exists in the createSlotImportJob function within Valkey's Slot Migration module. Manipulating the job_name argument can trigger an out-of-bounds read, exposing sensitive data to an attacker with network access. The defect allows exploitation from a remote source, meaning that any system exposed to untrusted traffic could be compromised. The vulnerability is publicly known and the associated patch is available.
Affected Systems
The flaw affects Valkey releases up to 9.5.4 on the 9.5.x line and up to 9.1.0 on the 9.1.x line. All other versions are considered unaffected.
Risk and Exploitability
The CVSS score of 6.9 reflects moderate severity; the EPSS score is not available, and the issue is not listed in the CISA KEV catalog, but the publicly available exploit means that attackers can readily target vulnerable systems. Remote exploitation is possible, so the risk is real for exposed deployments. Patching to 9.0.5 or 9.1.1 resolves the problem.
OpenCVE Enrichment