Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-90698

Опубликовано: 14 сент. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43. This vulnerability affects the function try_read_command_asciiauth of the file proto_text.c of the component mcmc Tokenizer. The manipulation results in out-of-bounds read. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 1.6.44 is able to resolve this issue. The patch is identified as af05c9302bba508b736c3da1d5670f63fe8b7db4. You should upgrade the affected component.

A flaw was found in memcached. A remote attacker could exploit an out-of-bounds read vulnerability in the try_read_command_asciiauth function. This could lead to a Denial of Service (DoS) condition, making the service unavailable to legitimate users.

Меры по смягчению последствий

To reduce exposure, restrict network access to the memcached service. Configure memcached to listen only on trusted interfaces or localhost, preventing remote attackers from reaching the vulnerable component. For example, modify the memcached service configuration to bind to 127.0.0.1 or a specific internal IP address. A service restart is required for changes to take effect and may temporarily impact services utilizing memcached.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10memcachedNot affected
Red Hat Enterprise Linux 10rhel10/memcachedNot affected
Red Hat Enterprise Linux 6memcachedNot affected
Red Hat Enterprise Linux 7memcachedNot affected
Red Hat Enterprise Linux 8memcachedNot affected
Red Hat Enterprise Linux 9memcachedNot affected
Red Hat Enterprise Linux 9rhel9/memcachedNot affected
Red Hat Hardened ImagesmemcachedAffected
Red Hat OpenStack Platform 13 (Queens)memcachedNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2532955memcached: memcached: Denial of Service due to out-of-bounds read

EPSS

Процентиль: 41%
0.00496
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 дня назад

A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43. This vulnerability affects the function try_read_command_asciiauth of the file proto_text.c of the component mcmc Tokenizer. The manipulation results in out-of-bounds read. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 1.6.44 is able to resolve this issue. The patch is identified as af05c9302bba508b736c3da1d5670f63fe8b7db4. You should upgrade the affected component.

CVSS3: 5.3
nvd
3 дня назад

A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43. This vulnerability affects the function try_read_command_asciiauth of the file proto_text.c of the component mcmc Tokenizer. The manipulation results in out-of-bounds read. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 1.6.44 is able to resolve this issue. The patch is identified as af05c9302bba508b736c3da1d5670f63fe8b7db4. You should upgrade the affected component.

CVSS3: 5.3
debian
3 дня назад

A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43. ...

CVSS3: 5.3
github
3 дня назад

A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43. This vulnerability affects the function try_read_command_asciiauth of the file proto_text.c of the component mcmc Tokenizer. The manipulation results in out-of-bounds read. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 1.6.44 is able to resolve this issue. The patch is identified as af05c9302bba508b736c3da1d5670f63fe8b7db4. You should upgrade the affected component.

EPSS

Процентиль: 41%
0.00496
Низкий

5.3 Medium

CVSS3