In memcached before 1.5.14, a NULL pointer dereference was found in the lru mode and lru temp_ttl commands. This causes a denial of service when parsing crafted lru command messages in process_lru_command in memcached.c.
The product dereferences a pointer that it expects to be valid but is NULL.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Memcached | Memcached | * | 1.5.14 (excluding) |
| Red Hat Enterprise Linux 8 | RedHat | memcached-0:1.5.9-3.el8 | * |
| Red Hat OpenStack Platform 13.0 (Queens) | RedHat | memcached-0:1.4.39-3.el7ost | * |
| Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS | RedHat | memcached-0:1.4.39-3.el7ost | * |
| Memcached | Ubuntu | bionic | * |
| Memcached | Ubuntu | cosmic | * |
| Memcached | Ubuntu | devel | * |
| Memcached | Ubuntu | disco | * |
| Memcached | Ubuntu | esm-infra/bionic | * |
| Memcached | Ubuntu | upstream | * |