Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:20884-1

Опубликовано: 02 июн. 2026
Источник: suse-cvrf

Описание

Security update for memcached

This update for memcached fixes the following issues

  • CVE-2026-47783: timing side-channel in SASL password database authentication (username) (bsc#1265873).
  • CVE-2026-47784: timing side-channel in SASL password database authentication (password) (bsc#1265881).

Список пакетов

openSUSE Leap 16.0
memcached-1.6.38-160000.3.1
memcached-devel-1.6.38-160000.3.1

Описание

In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.


Затронутые продукты
openSUSE Leap 16.0:memcached-1.6.38-160000.3.1
openSUSE Leap 16.0:memcached-devel-1.6.38-160000.3.1

Ссылки

Описание

In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass.


Затронутые продукты
openSUSE Leap 16.0:memcached-1.6.38-160000.3.1
openSUSE Leap 16.0:memcached-devel-1.6.38-160000.3.1

Ссылки