In memcached before 1.5.14, a NULL pointer dereference was found in the lru mode and lru temp_ttl commands. This causes a denial of service when parsing crafted lru command messages in process_lru_command in memcached.c.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Memcached | Memcached | * | 1.5.14 (excluding) |
Red Hat Enterprise Linux 8 | RedHat | memcached-0:1.5.9-3.el8 | * |
Red Hat OpenStack Platform 13.0 (Queens) | RedHat | memcached-0:1.4.39-3.el7ost | * |
Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS | RedHat | memcached-0:1.4.39-3.el7ost | * |
Memcached | Ubuntu | bionic | * |
Memcached | Ubuntu | cosmic | * |
Memcached | Ubuntu | devel | * |
Memcached | Ubuntu | disco | * |
Memcached | Ubuntu | upstream | * |