Skip to content

Commit e32a4e4

Browse files
Kanishk-BansalKanishk Bansal
andauthored
Upgrade valkey to 8.0.6 for CVE-2025-49844 CVE-2025-46817 CVE-2025-46818 CVE-2025-46819 (microsoft#14835)
Signed-off-by: Kanishk Bansal <[email protected]> Co-authored-by: Kanishk Bansal <[email protected]>
1 parent ad3982c commit e32a4e4

File tree

7 files changed

+19
-95
lines changed

7 files changed

+19
-95
lines changed

SPECS/valkey/CVE-2025-27151.patch

Lines changed: 0 additions & 30 deletions
This file was deleted.

SPECS/valkey/CVE-2025-49112.patch

Lines changed: 0 additions & 26 deletions
This file was deleted.
Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -1,30 +1,30 @@
1-
From d9f795c8181d2db70626b7d43ebb2e6e8d2fbed8 Mon Sep 17 00:00:00 2001
2-
From: Rohit Rawat <xordux@gmail.com>
3-
Date: Tue, 29 Oct 2024 14:10:20 +0000
1+
From e10d46d1cb92c25d1f72735661496fe8527d499c Mon Sep 17 00:00:00 2001
2+
From: Kanishk Bansal <kanbansal@microsoft.com>
3+
Date: Wed, 8 Oct 2025 06:42:39 +0000
44
Subject: [PATCH] Disable flaky mem defrag tests
55

66
---
77
tests/unit/memefficiency.tcl | 2 ++
88
1 file changed, 2 insertions(+)
99

1010
diff --git a/tests/unit/memefficiency.tcl b/tests/unit/memefficiency.tcl
11-
index d5a6a6e..37e1711 100644
11+
index 4dc04f6..7418980 100644
1212
--- a/tests/unit/memefficiency.tcl
1313
+++ b/tests/unit/memefficiency.tcl
14-
@@ -720,6 +720,7 @@ run_solo {defrag} {
14+
@@ -721,6 +721,7 @@ run_solo {defrag} {
1515
}
1616
}
1717

1818
+ if {0} {
19-
start_cluster 1 0 {tags {"defrag external:skip cluster"} overrides {appendonly yes auto-aof-rewrite-percentage 0 save ""}} {
19+
start_cluster 1 0 {tags {"defrag external:skip cluster"} overrides {appendonly yes auto-aof-rewrite-percentage 0 save "" lazyfree-lazy-user-del no}} {
2020
test_active_defrag "cluster"
2121
}
22-
@@ -727,4 +728,5 @@ run_solo {defrag} {
23-
start_server {tags {"defrag external:skip standalone"} overrides {appendonly yes auto-aof-rewrite-percentage 0 save ""}} {
22+
@@ -728,4 +729,5 @@ run_solo {defrag} {
23+
start_server {tags {"defrag external:skip standalone"} overrides {appendonly yes auto-aof-rewrite-percentage 0 save "" lazyfree-lazy-user-del no}} {
2424
test_active_defrag "standalone"
2525
}
2626
+ }
2727
} ;# run_solo
2828
--
29-
2.39.4
29+
2.45.4
3030

SPECS/valkey/valkey-conf.patch

Lines changed: 0 additions & 22 deletions
This file was deleted.
Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
{
22
"Signatures": {
3-
"valkey-8.0.4.tar.gz": "55c12a25f67ef19b615c76b6cb0c92d12753d76eb8d38b31d30e299c3490cdf2"
3+
"valkey-8.0.6.tar.gz": "f8d15c257a3619e0e42e68998e9dc16536009d257662efa4c62ef7d08a71b0dd"
44
}
55
}

SPECS/valkey/valkey.spec

Lines changed: 7 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,17 +1,15 @@
11
Summary: advanced key-value store
22
Name: valkey
3-
Version: 8.0.4
3+
Version: 8.0.6
44
Release: 1%{?dist}
55
License: BSD
66
Vendor: Microsoft Corporation
77
Distribution: Azure Linux
88
Group: Applications/Databases
99
URL: https://valkey.io/
1010
Source0: https://github.com/valkey-io/valkey/archive/refs/tags/%{version}.tar.gz#/%{name}-%{version}.tar.gz
11-
Patch0: valkey-conf.patch
12-
Patch1: disable-mem-defrag-tests.patch
13-
Patch2: CVE-2025-49112.patch
14-
Patch3: CVE-2025-27151.patch
11+
Patch0: disable-mem-defrag-tests.patch
12+
1513
BuildRequires: gcc
1614
BuildRequires: make
1715
BuildRequires: openssl-devel
@@ -86,6 +84,10 @@ exit 0
8684
%config(noreplace) %attr(0640, %{name}, %{name}) %{_sysconfdir}/valkey.conf
8785

8886
%changelog
87+
* Wed Oct 08 2025 Kanishk Bansal <[email protected]> - 8.0.6-1
88+
- Upgrade to 8.0.6 for CVE-2025-49844 CVE-2025-46817 CVE-2025-46818 CVE-2025-46819
89+
- Remove older patches of CVE-2025-27151 CVE-2025-49112
90+
8991
* Tue Jul 22 2025 Kevin Lockwood <[email protected]> - 8.0.4-1
9092
- Upgrade to 8.0.4 to fix CVE-2025-32023, CVE-2025-48367
9193

cgmanifest.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -29716,8 +29716,8 @@
2971629716
"type": "other",
2971729717
"other": {
2971829718
"name": "valkey",
29719-
"version": "8.0.4",
29720-
"downloadUrl": "https://github.com/valkey-io/valkey/archive/refs/tags/8.0.4.tar.gz"
29719+
"version": "8.0.6",
29720+
"downloadUrl": "https://github.com/valkey-io/valkey/archive/refs/tags/8.0.6.tar.gz"
2972129721
}
2972229722
}
2972329723
},

0 commit comments

Comments
 (0)