CVE-2022-48571: High severity memcached vulnerability
Published Aug 22, 2023
·Updated
memcached 1.6.7 allows a Denial of Service via multi-packet uploads in UDP.
Affected Software
6 affected componentsFixes available
debian/memcached<=1.5.6-1.1
1.5.6-1.1+deb10u11.6.9+dfsg-11.6.18-11.6.21-2
ubuntu/memcached<1.6.8+dfsg-1
1.6.8+dfsg-1
ubuntu/memcached<1.5.6-0ubuntu1.2+
1.5.6-0ubuntu1.2+
ubuntu/memcached<1.5.22-2ubuntu0.3
1.5.22-2ubuntu0.3
ubuntu/memcached<1.4.25-2ubuntu1.5+
1.4.25-2ubuntu1.5+
Memcached Memcached=1.6.7
Remediation
Event History
Aug 22, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Sep 19, 2023
Data Sourced
06:46 PM
Description
Frequently Asked Questions
1
What is CVE-2022-48571?
CVE-2022-48571 is a vulnerability in memcached 1.6.7 that allows a Denial of Service via multi-packet uploads in UDP.
2
How can the CVE-2022-48571 vulnerability be exploited?
The CVE-2022-48571 vulnerability can be exploited by an attacker sending specially crafted multi-packet uploads in UDP to the affected memcached server, causing it to crash and become unresponsive.
3
What is the severity of CVE-2022-48571?
CVE-2022-48571 has a severity rating of high, with a severity value of 7.5.
4
Which versions of memcached are affected by CVE-2022-48571?
The vulnerability affects only memcached version 1.6.7.
5
How can I fix the CVE-2022-48571 vulnerability?
To fix the CVE-2022-48571 vulnerability, update memcached to a version that includes the fix, such as 1.6.9+dfsg-1 or 1.6.18-1.