Back

HIGH

memcached: Memcached: Information disclosure via timing side channel

Published May 20, 2026

Description

In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass.

Affected products

Remediation

Red Hat mitigation

To mitigate this issue, restrict network access to the memcached service to only trusted clients and networks using firewall rules. If SASL authentication is not strictly required, consider disabling it. If SASL is necessary, ensure that strong, unique passwords are used and rotated regularly. Example firewall rule (adjust port and source as needed): `firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="<TRUSTED_IP_RANGE>" port port="11211" protocol="tcp" accept'` `firewall-cmd --reload` To bind memcached to localhost, edit `/etc/sysconfig/memcached` and set `OPTIONS="-l 127.0.0.1"`. Restart the memcached service: `systemctl restart memcached` Note that restarting the memcached service will clear all cached data.

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 20, 2026
Updated May 20, 2026
Reserved May 20, 2026
CISA Vulnrichment
Updated May 20, 2026
NVD
Status Analyzed
Modified Jul 24, 2026
Red Hat
Severity Moderate
Public date May 20, 2026