CVE-2026-90698: memcached mcmc Tokenizer proto_text.c try_read_command_asciiauth out-of-bounds
A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43. This vulnerability affects the function tryreadcommandasciiauth of the file prototext.c of the component mcmc Tokenizer. The manipulation results in out-of-bounds read. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 1.6.44 is able to resolve this issue. The patch is identified as af05c9302bba508b736c3da1d5670f63fe8b7db4. You should upgrade the affected component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
memcached mcmc Tokenizer proto_text.c try_read_command_asciiauthto a version that resolves this vulnerability.Fixed in 1.6.44 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch af05c9302bba508b736c3da1d5670f63fe8b7db4
Event History
Frequently Asked Questions
Which deployments are affected?
The issue affects memcached versions 1.6.41, 1.6.42, and 1.6.43 in the mcmc Tokenizer component.
Does exploitation require authentication or user interaction?
No authentication or user interaction is required according to the supplied severity vector. The attack can be launched remotely and has low attack complexity.
Is public exploit code available?
Yes. The exploit has been released publicly and may be used in attacks.
What is the recommended remediation?
Upgrade memcached to version 1.6.44. The associated patch is af05c9302bba508b736c3da1d5670f63fe8b7db4.