Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-47784

Опубликовано: 20 мая 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass.

A flaw was found in memcached. This vulnerability involves a timing side channel during SASL (Simple Authentication and Security Layer) password database authentication. A remote attacker could potentially exploit the timing differences in the password verification process to infer sensitive password data. This could lead to unauthorized access to the memcached instance.

Меры по смягчению последствий

To mitigate this issue, restrict network access to the memcached service to only trusted clients and networks using firewall rules. If SASL authentication is not strictly required, consider disabling it. If SASL is necessary, ensure that strong, unique passwords are used and rotated regularly. Example firewall rule (adjust port and source as needed): firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="<TRUSTED_IP_RANGE>" port port="11211" protocol="tcp" accept' firewall-cmd --reload To bind memcached to localhost, edit /etc/sysconfig/memcached and set OPTIONS="-l 127.0.0.1". Restart the memcached service: systemctl restart memcached Note that restarting the memcached service will clear all cached data.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10memcachedFix deferred
Red Hat Enterprise Linux 6memcachedFix deferred
Red Hat Enterprise Linux 7memcachedFix deferred
Red Hat Enterprise Linux 8memcachedFix deferred
Red Hat Enterprise Linux 9memcachedFix deferred
Red Hat Hardened Imagesmemcached-main-1.6.42-0.1.hum1FixedRHSA-2026:2326104.06.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-208
https://bugzilla.redhat.com/show_bug.cgi?id=2480088memcached: Memcached: Information disclosure via timing side channel

EPSS

Процентиль: 42%
0.0055
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
3 месяца назад

In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass.

CVSS3: 8.1
nvd
3 месяца назад

In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass.

CVSS3: 8.1
msrc
3 месяца назад

In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass.

CVSS3: 8.1
debian
3 месяца назад

In memcached before 1.6.42, password data for SASL password database a ...

CVSS3: 8.1
github
3 месяца назад

In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass.

EPSS

Процентиль: 42%
0.0055
Низкий

5.9 Medium

CVSS3