CVE-2019-15026: High severity Memcached Memcached vulnerability
Last updated 25 August 2025
Other sources
memcached 1.5.16, when UNIX sockets are used, has a stack-based buffer over-read in conntostr in memcached.c.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-15026?
CVE-2019-15026 is a vulnerability in memcached 1.5.16 that leads to a stack-based buffer over-read when UNIX sockets are used.
What is the severity of CVE-2019-15026?
CVE-2019-15026 has a severity level of high with a CVSS score of 7.5.
Which software versions are affected by CVE-2019-15026?
memcached versions 1.5.16, 1.5.6-0ubuntu1.2, 1.5.10-0ubuntu1.19.04.2, 1.4.25-2ubuntu1.5, 1.6.9+dfsg-1, 1.6.18-1, and 1.6.22-1 are affected by CVE-2019-15026.
How can I fix CVE-2019-15026?
To fix CVE-2019-15026, update your memcached installation to version 1.5.6-0ubuntu1.2, 1.5.10-0ubuntu1.19.04.2, 1.4.25-2ubuntu1.5, 1.6.9+dfsg-1, 1.6.18-1, or 1.6.22-1.
Where can I find more information about CVE-2019-15026?
You can find more information about CVE-2019-15026 in the references: http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00060.html, https://github.com/memcached/memcached/commit/554b56687a19300a75ec24184746b5512580c819, and https://github.com/memcached/memcached/wiki/ReleaseNotes1517.