The following vulnerability was published for valkey (and same code in
redict, redis seems present, cloning the bug for further evaluation in
the respective sources).
CVE-2025-49112[0]:
| setDeferredReply in networking.c in Valkey through 8.1.1 has an
| integer underflow for prev->size - prev->used.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.