-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4791-1 [email protected]
https://www.debian.org/lts/security/ Abhijith PA
September 23, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------
Package : memcached
Version : 1.6.18-1+deb12u1
CVE ID : CVE-2023-46852 CVE-2023-46853 CVE-2026-47783
CVE-2026-47784
Multiple vulnerabilities were found in memcached, high-performance
in-memory object caching system.
CVE-2023-46852
a buffer overflow exists when processing multiget requests in
proxy mode, if there are many spaces after the "get" substring
CVE-2023-46853
an off-by-one error exists when processing proxy requests in proxy
mode, if \n is used instead of \r\n.
CVE-2026-47783
username data for SASL password database authentication has a
timing side channel because a loop exits as soon as a valid
username is found by sasl_server_userdb_checkpass.
CVE-2026-47784
password data for SASL password database authentication has a
timing side channel because memcmp is used by
sasl_server_userdb_checkpass.
For Debian 12 bookworm, these problems have been fixed in version
1.6.18-1+deb12u1.
We recommend that you upgrade your memcached packages.
For the detailed security status of memcached please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/memcached
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEE7xPqJqaY/zX9fJAuhj1N8u2cKO8FAmqzS8YACgkQhj1N8u2c
KO/4chAAkXBAjGQ2pY5LPQBFPpCAnOsBUZpa7NfZLsRN8awNU+3kwqj/qtRuQWeI
DMHtXqxh4f00Z8B7QcTM+hzNh0VytvEwbMtBQTTwRe0ONrMGbpw7xDwT81Af2s4g
Nw4QHJP4WrzoFVL2k509agM/SLsyTy+W0E+MIkhk2A+5Z9mAVJBu+LPBBZBt8e/d
OLdsW5S1lVKeOkg0cqlKBaIzm9AZKUsvXAeHrehsLiWoLn2YbOJ4vSBgOaMa00+b
YN6CxgdAkF+izlbUUnCyNJXuoxj8jgxsZYAt/NoVZXY7hWB9vQdV0GWyg7joyGW0
YFZxq7tvaZx0MBzk+uqC+Kww61Y45Jt30wan5VWdvW/TvGXH8ZSKnCueXCPABCDt
KqM18rPVAv+enNQ6JzTE7l8BYmUFMB5utV/icnpNgzG8YbHoN/AF6x6Pj5uqIkl6
jEGXzpLbzsNk8uDlWdgEHuGumPcpq+ZRMY4L5uEp6tlylkwajZ2nKvV0rZc9f59q
z9oL/TU2pSOf4tTIhvPFFxqVt1dOxm6i7veSsls4V15TJHBJ9JBsUizWCjnt02zf
izMZWCCuHY2wHHN1heXyPJUskm/wXCfCXTM0eNtUytzIpjAL9w92+bU7VhzF7H6u
P+nQlKt+bIk6g6jYceqgyAYrdpmw9kI5qICmo7TsjvoG3R0w9SM=
=bZMS
-----END PGP SIGNATURE-----