memcached: null-pointer dereference in "lru mode" and "lru temp_ttl" causing denial of service
Published Apr 29, 2019
7.5
HIGHCVSS 3.0
EPSS 2.96%
Description
In memcached before 1.5.14, a NULL pointer dereference was found in the "lru mode" and "lru temp_ttl" commands. This causes a denial of service when parsing crafted lru command messages in process_lru_command in memcached.c.
Affected products
No data.
Configuration 2
- 18.04
- 18.10
- 19.04
No data.
Red Hat Enterprise Linux 8
memcached-0:1.5.9-3.el8
Fixed · RHSA-2020:1576
Red Hat OpenStack Platform 13.0 (Queens)
memcached-0:1.4.39-3.el7ost
Fixed · RHSA-2020:5583
Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS
memcached-0:1.4.39-3.el7ost
Fixed · RHSA-2020:5583
Red Hat Enterprise Linux 6
memcached
Not affected
Red Hat Enterprise Linux 7
memcached
Not affected
Red Hat OpenStack Platform 10 (Newton)
memcached
Will not fix
Red Hat OpenStack Platform 14 (Rocky)
memcached
Affected
Red Hat OpenStack Platform 9 (Mitaka)
memcached
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | memcached-0:1.5.9-3.el8 | Fixed | RHSA-2020:1576 |
| Red Hat OpenStack Platform 13.0 (Queens) | memcached-0:1.4.39-3.el7ost | Fixed | RHSA-2020:5583 |
| Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS | memcached-0:1.4.39-3.el7ost | Fixed | RHSA-2020:5583 |
| Red Hat Enterprise Linux 6 | memcached | Not affected | n/a |
| Red Hat Enterprise Linux 7 | memcached | Not affected | n/a |
| Red Hat OpenStack Platform 10 (Newton) | memcached | Will not fix | n/a |
| Red Hat OpenStack Platform 14 (Rocky) | memcached | Affected | n/a |
| Red Hat OpenStack Platform 9 (Mitaka) | memcached | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The vulnerable code is not present in the versions of memcached as shipped in Red Hat Enterprise Linux 6 and 7, so they are not affected by this flaw.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (20 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.96% (0.02958) | 86.71th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.96% (0.02958) | 85.36th | v5 (v2026.06.15) |
| Nov 21, 2025 | 1.64% (0.01644) | 81.39th | v4 (v2025.03.14) |
| Nov 18, 2025 | 2.72% (0.02720) | 84.64th | v4 (v2025.03.14) |
| Jun 19, 2025 | 1.55% (0.01551) | 80.55th | v4 (v2025.03.14) |
| Mar 30, 2025 | 2.57% (0.02569) | 84.20th | v4 (v2025.03.14) |
| Mar 29, 2025 | 6.36% (0.06363) | 84.56th | v4 (v2025.03.14) |
| Mar 17, 2025 | 2.57% (0.02569) | 84.51th | v4 (v2025.03.14) |
| Dec 17, 2024 | 9.63% (0.09630) | 94.78th | v3 (v2023.03.01) |
| Sep 19, 2024 | 21.57% (0.21568) | 96.54th | v3 (v2023.03.01) |
| Apr 5, 2023 | 19.08% (0.19081) | 95.45th | v3 (v2023.03.01) |
| Mar 20, 2023 | 17.20% (0.17195) | 95.22th | v3 (v2023.03.01) |
| Mar 7, 2023 | 13.36% (0.13363) | 94.63th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.11% (0.01108) | 55.18th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.11% (0.01108) | 51.54th | v2 (v2022.01.01) |
| Feb 4, 2022 | 14.86% (0.14862) | 91.25th | v2 (v2022.01.01) |
| Feb 3, 2022 | 8.63% (0.08626) | 85.56th | v1 |
| Jan 6, 2022 | 8.63% (0.08626) | 85.39th | v1 |
| Jan 5, 2022 | 2.06% (0.02061) | 77.63th | v5 (v2026.06.15) |
| Apr 14, 2021 | 2.06% (0.02061) | 0.00th | v1 |
References (11)
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00060.html vendor-advisoryx_refsource_SUSE
- https://access.redhat.com/security/cve/CVE-2019-11596 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1706001 Issue Tracking
- https://github.com/memcached/memcached/commit/d35334f368817a77a6bd1f33c6a5676b2c402c02 x_refsource_MISCPatchThird Party Advisory
- https://github.com/memcached/memcached/compare/ee1cfe3...50bdc9f x_refsource_MISCPatch
- https://github.com/memcached/memcached/issues/474 x_refsource_MISCExploitThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UUE3QBMP5UWTXMPKJREUICH6DIK6SOBX/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y2CCWRM4LHB253KG5SPOKRVDCXQX5VZR/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2019-11596
- https://usn.ubuntu.com/3963-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-11596
Change history (0)
No recorded changes yet.