Integer Underflow Vulnerability in Valkey Networking Component
CVE-2025-49112

3.1LOW

Key Information:

Vendor

Valkey

Status
Vendor
CVE Published:
2 June 2025

What is CVE-2025-49112?

The Valkey networking component through version 8.1.1 contains a vulnerability due to an integer underflow in the setDeferredReply function. This flaw arises from the calculation of 'prev->size - prev->used', which can lead to unintended behavior and may be exploited in specific circumstances. Users should ensure they are on the latest version and monitor potential impacts related to network operations.

Affected Version(s)

Valkey 0 <= 8.1.1

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.