Описание
Security update for memcached
This update for memcached fixes the following issues
- CVE-2026-47783: timing side-channel in SASL password database authentication (username) (bsc#1265873).
- CVE-2026-47784: timing side-channel in SASL password database authentication (password) (bsc#1265881).
Список пакетов
openSUSE Leap 16.0
memcached-1.6.38-160000.3.1
memcached-devel-1.6.38-160000.3.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1265873
- SUSE Bug 1265881
- SUSE CVE CVE-2026-47783 page
- SUSE CVE CVE-2026-47784 page
Описание
In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.
Затронутые продукты
openSUSE Leap 16.0:memcached-1.6.38-160000.3.1
openSUSE Leap 16.0:memcached-devel-1.6.38-160000.3.1
Ссылки
- CVE-2026-47783
- SUSE Bug 1265873
Описание
In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass.
Затронутые продукты
openSUSE Leap 16.0:memcached-1.6.38-160000.3.1
openSUSE Leap 16.0:memcached-devel-1.6.38-160000.3.1
Ссылки
- CVE-2026-47784
- SUSE Bug 1265881