{"id":"CVE-2026-82677","summary":"valkey-io valkey Module Timer module.c moduleTimerHandler double free","details":"A vulnerability was determined in valkey-io valkey 9.1.0. Impacted is the function moduleTimerHandler of the file src/module.c of the component Module Timer Subsystem. This manipulation causes double free. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Patch name: b349fe2821e3998534b1454c1b64a478daf8c6b7. To fix this issue, it is recommended to deploy a patch.","modified":"2026-09-02T08:05:45.313862Z","published":"2026-08-31T10:00:15.053Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-119","CWE-415"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82677.json"},"references":[{"type":"WEB","url":"https://github.com/valkey-io/valkey/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82677.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-82677"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-82677"},{"type":"ADVISORY","url":"https://vuldb.com/submit/893959"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/397172"},{"type":"REPORT","url":"https://github.com/valkey-io/valkey/issues/4200"},{"type":"REPORT","url":"https://vuldb.com/vuln/397172/cti"},{"type":"FIX","url":"https://github.com/valkey-io/valkey/commit/b349fe2821e3998534b1454c1b64a478daf8c6b7"},{"type":"FIX","url":"https://github.com/valkey-io/valkey/pull/4211"},{"type":"EVIDENCE","url":"https://github.com/user-attachments/files/30118801/PoC.zip"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/valkey-io/valkey","events":[{"introduced":"c9e8005e9d0ec817e26c7db318861cb821409249"},{"fixed":"b349fe2821e3998534b1454c1b64a478daf8c6b7"}],"database_specific":{"extracted_events":[{"introduced":"9.1.0"},{"last_affected":"9.1.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["9.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82677.json","vanir_signatures_modified":"2026-09-02T08:05:45Z","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["121424084538841979303371684067119623936","184172033092886764967057584451512310012","23763138507377313270743289103296802350","53557224944119540552029822075154181490","335627178093124097414656039686885628636","180911272441217126914259233718729396533","76251647179270472373396840484895292057","191059738845168834836956503359775452072","70926986156126347839965255119912938867","232798187513881962608299090294875735235"],"threshold":0.9},"id":"CVE-2026-82677-3713ad9c","signature_type":"Line","signature_version":"v1","source":"https://github.com/valkey-io/valkey/commit/b349fe2821e3998534b1454c1b64a478daf8c6b7","target":{"file":"tests/modules/timer.c"}},{"digest":{"function_hash":"181002746710278198057415400298666164805","length":926},"id":"CVE-2026-82677-bfdace78","signature_type":"Function","signature_version":"v1","source":"https://github.com/valkey-io/valkey/commit/b349fe2821e3998534b1454c1b64a478daf8c6b7","target":{"file":"src/module.c","function":"moduleTimerHandler"},"deprecated":false},{"digest":{"function_hash":"223872119029403364301683718358855343745","length":622},"id":"CVE-2026-82677-d2060176","signature_type":"Function","signature_version":"v1","source":"https://github.com/valkey-io/valkey/commit/b349fe2821e3998534b1454c1b64a478daf8c6b7","target":{"file":"tests/modules/timer.c","function":"ValkeyModule_OnLoad"},"deprecated":false},{"signature_version":"v1","source":"https://github.com/valkey-io/valkey/commit/b349fe2821e3998534b1454c1b64a478daf8c6b7","target":{"file":"src/module.c"},"deprecated":false,"digest":{"line_hashes":["296600120506627947378667650651849215320","249043444977729417223967385422382802430","3896363355649836795860685149567679731","66443840598751723807212496914308728363","217843375045813198240432110884070006111","277660404437707427574304317542096099240","177115730006976117751042488760995221490","68512649465367817025158534011933578786","253505895709609749406755755212734231586","65261301973095328416481032669559439244","142927469614529443823430184823995116761","307598280944125561519196389387933560061"],"threshold":0.9},"id":"CVE-2026-82677-e076e4e8","signature_type":"Line"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"}]}