UbuntuUpdates.org

Package "memcached"

Name: memcached

Description:

High-performance in-memory object caching system

Latest version: 1.6.24-1ubuntu0.2
Release: noble (24.04)
Level: updates
Repository: main
Homepage: https://memcached.org/

Links


Download "memcached"


Other versions of "memcached" in Noble

Repository Area Version
base main 1.6.24-1build3
security main 1.6.24-1ubuntu0.2

Changelog

Version: 1.6.24-1ubuntu0.2 2026-09-01 05:07:27 UTC

memcached (1.6.24-1ubuntu0.2) noble-security; urgency=medium

  * SECURITY UPDATE: out-of-bounds heap write in the LRU crawler dump path
    when an idle client stalls reading a dump (LP: #2161693):
    - debian/patches/lp2161693-0-fix-lru-crawler-buffer-overflow-on-idle-client.patch:
      backport 7eeac6e9, retry on poll() timeout instead of a false flush.
    - debian/patches/lp2161693-1-fix-lru-crawler-unlock-of-unlocked-mutex.patch:
      backport ea35f44, lock lru_locks[i] before lru_crawler_class_done().

 -- Seyeong Kim Fri, 24 Jul 2026 03:09:54 +0000

Source diff to previous version
2161693 memcached: heap buffer overflow in LRU crawler dump (lru_crawler metadump) on an idle client

Version: 1.6.24-1ubuntu0.1 2026-05-27 16:07:34 UTC

  memcached (1.6.24-1ubuntu0.1) noble-security; urgency=medium

  * SECURITY UPDATE: SASL password timing side-channel
    - debian/patches/CVE-2026-4778x.patch: Fix timing side-channel in SASL
      password database authentication in sasl_defs.c.
    - CVE-2026-47783
    - CVE-2026-47784

 -- Marc Deslauriers <email address hidden> Fri, 22 May 2026 13:12:42 -0400

CVE-2026-4778 A weakness has been identified in SourceCodester Sales and Inventory System 1.0. This vulnerability affects unknown code of the file update_category.
CVE-2026-47783 In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid
CVE-2026-47784 In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_u



About   -   Send Feedback to @ubuntu_updates