Integer Underflow Vulnerability in Valkey Networking Component
CVE-2025-49112
3.1LOW
What is CVE-2025-49112?
The Valkey networking component through version 8.1.1 contains a vulnerability due to an integer underflow in the setDeferredReply function. This flaw arises from the calculation of 'prev->size - prev->used', which can lead to unintended behavior and may be exploited in specific circumstances. Users should ensure they are on the latest version and monitor potential impacts related to network operations.
Affected Version(s)
Valkey 0 <= 8.1.1