CVE Vulnerabilities

CVE-2019-11596

NULL Pointer Dereference

Published: Apr 29, 2019 | Modified: Nov 07, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

In memcached before 1.5.14, a NULL pointer dereference was found in the lru mode and lru temp_ttl commands. This causes a denial of service when parsing crafted lru command messages in process_lru_command in memcached.c.

Weakness

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Affected Software

Name Vendor Start Version End Version
Memcached Memcached * 1.5.14 (excluding)
Red Hat Enterprise Linux 8 RedHat memcached-0:1.5.9-3.el8 *
Red Hat OpenStack Platform 13.0 (Queens) RedHat memcached-0:1.4.39-3.el7ost *
Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS RedHat memcached-0:1.4.39-3.el7ost *
Memcached Ubuntu bionic *
Memcached Ubuntu cosmic *
Memcached Ubuntu devel *
Memcached Ubuntu disco *
Memcached Ubuntu upstream *

Potential Mitigations

References