memcached: Memcached: Information disclosure via timing side channel
Published May 20, 2026
8.1
HIGHCVSS 3.1
EPSS 0.55%
Description
In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass.
Affected products
-
- Version 0StatusaffectedConstraints<1.6.42
- Version
No data.
Red Hat Hardened Images
memcached-main-1.6.42-0.1.hum1
Fixed · RHSA-2026:23261
Red Hat Enterprise Linux 10
memcached
Fix deferred
Red Hat Enterprise Linux 6
memcached
Fix deferred
Red Hat Enterprise Linux 7
memcached
Fix deferred
Red Hat Enterprise Linux 8
memcached
Fix deferred
Red Hat Enterprise Linux 9
memcached
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Hardened Images | memcached-main-1.6.42-0.1.hum1 | Fixed | RHSA-2026:23261 |
| Red Hat Enterprise Linux 10 | memcached | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | memcached | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | memcached | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | memcached | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | memcached | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
To mitigate this issue, restrict network access to the memcached service to only trusted clients and networks using firewall rules. If SASL authentication is not strictly required, consider disabling it. If SASL is necessary, ensure that strong, unique passwords are used and rotated regularly. Example firewall rule (adjust port and source as needed): `firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="<TRUSTED_IP_RANGE>" port port="11211" protocol="tcp" accept'` `firewall-cmd --reload` To bind memcached to localhost, edit `/etc/sysconfig/memcached` and set `OPTIONS="-l 127.0.0.1"`. Restart the memcached service: `systemctl restart memcached` Note that restarting the memcached service will clear all cached data.
References (7)
- https://access.redhat.com/security/cve/CVE-2026-47784 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2480088 Issue Tracking
- https://github.com/memcached/memcached/commit/d13f282b4bce33a9c33b8a1bbf07f12114160fed Patch
- https://github.com/memcached/memcached/compare/1.6.41...1.6.42 Release Notes
- https://github.com/memcached/memcached/wiki/ReleaseNotes1642 Release Notes
- https://nvd.nist.gov/vuln/detail/CVE-2026-47784
- https://www.cve.org/CVERecord?id=CVE-2026-47784
Change history (0)
No recorded changes yet.