memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free() that can result in data corruption and deadlocks due to items existing in hash table being reused from free list. This attack appear to be exploitable via network connectivity to the memcached service. This vulnerability appears to have been fixed in 1.4.37 and later.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade memcached | Jun 7, 2018 | Mar 13, 2018 |
| Huawei Euleros 2_0_sp1 | — | Upgrade memcached | May 29, 2018 | Mar 13, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade memcached | Dec 4, 2019 | Mar 13, 2018 |
| Huawei Euleros 2_0_sp3 | — | Upgrade memcached | Jul 3, 2018 | Mar 13, 2018 |
| Oracle Solaris | — | Upgrade service/memcached to version 1.5.11-11.4.5.0.1.2.0 on Solaris 11.4 | Feb 20, 2019 | Mar 13, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 13, 2018 |
| Suse | — | Upgrade memcached-develUpgrade memcached | Feb 4, 2022 | Mar 13, 2018 |
| Ubuntu | — | Upgrade memcached | Apr 25, 2018 | Mar 13, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub