CVE-2026-47784: High severity Memcached Memcached vulnerability
In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by saslserveruserdbcheckpass.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/memcachedto a version that resolves this vulnerability.Fixed in 1.6.9+dfsg-1+deb11u1Fixed in 1.6.42-1 - Upgrade
Upgrade
memcachedto a version that resolves this vulnerability.Fixed in 1.6.42
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47784?
CVE-2026-47784 has a high severity due to its potential exploitation through timing side channel attacks.
How do I fix CVE-2026-47784?
To fix CVE-2026-47784, upgrade to memcached version 1.6.42 or later which includes the necessary patches.
What type of attack is CVE-2026-47784 associated with?
CVE-2026-47784 is associated with timing side channel attacks that can compromise SASL password data.
What versions of memcached are affected by CVE-2026-47784?
CVE-2026-47784 affects all versions of memcached prior to 1.6.42.
What is the impact of exploiting CVE-2026-47784?
Exploiting CVE-2026-47784 may allow attackers to gain unauthorized access to sensitive information by compromising password data.