Home

Description

setDeferredReply in networking.c in Valkey through 8.1.1 has an integer underflow for prev->size - prev->used.

PUBLISHED Reserved 2025-06-02 | Published 2025-06-02 | Updated 2025-06-02 | Assigner mitre




LOW: 3.1CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

Problem types

CWE-191 Integer Underflow (Wrap or Wraparound)

Product status

Default status
unknown

Any version
affected

References

github.com/...db29bfd1c033e27f9d519a2f8ccbb/src/networking.c

github.com/valkey-io/valkey/pull/2101

github.com/...44cb153392fc96bdba43eae56e17f/src/networking.c

cve.org (CVE-2025-49112)

nvd.nist.gov (CVE-2025-49112)

Download JSON