CVE-2022-48571
published 2023-08-22CVE-2022-48571: memcached 1.6.7 allows a Denial of Service via multi-packet uploads in UDP.
PriorityP335high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.91%
56.1th percentile
memcached 1.6.7 allows a Denial of Service via multi-packet uploads in UDP.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | memcached | < memcached 1.6.8+dfsg-1 (bookworm) | memcached 1.6.8+dfsg-1 (bookworm) |
| memcached | memcached | — | — |
| memcached | memcached | >= 0 < 1.6.8+dfsg-1 | 1.6.8+dfsg-1 |
| memcached | memcached | >= 0 < 1.6.8+dfsg-1 | 1.6.8+dfsg-1 |
| memcached | memcached | >= 0 < 1.6.8+dfsg-1 | 1.6.8+dfsg-1 |
| memcached | memcached | >= 0 < 1.6.8+dfsg-1 | 1.6.8+dfsg-1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Memcached vulnerability
vendor_ubuntu·2023-09-19
CVE-2022-48571 Memcached vulnerability
Title: Memcached vulnerability
Summary: Memcached could be made to denial of service.
It was discovered that Memcached incorrectly handled certain multi-packet
uploads in UDP. An attacker could possibly use this issue to cause a
denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
memcached: Denial of Service via multi-packet uploads in UDP
vendor_redhat·2023-08-22·CVSS 7.5
CVE-2022-48571 [HIGH] CWE-400 memcached: Denial of Service via multi-packet uploads in UDP
memcached: Denial of Service via multi-packet uploads in UDP
memcached 1.6.7 allows a Denial of Service via multi-packet uploads in UDP.
A buffer overflow flaw was found in memcached. This issue occurs via multi-packet uploads in UDP, leading to a denial of service.
Statement: Red Hat Enterprise Linux 7, 8 & 9 are not vulnerable as the issue is already fixed in memcached 1.6.8 and memcached 1.6.9.
Mitigation: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: memcached (Red Hat Enterprise Linux 6) - Not affected
Package: memcached (Red Hat Enterprise Linux 7) - Not affected
Package: memcached (R
Debian
CVE-2022-48571: memcached - memcached 1.6.7 allows a Denial of Service via multi-packet uploads in UDP.
vendor_debian·2022·CVSS 7.5
CVE-2022-48571 [HIGH] CVE-2022-48571: memcached - memcached 1.6.7 allows a Denial of Service via multi-packet uploads in UDP.
memcached 1.6.7 allows a Denial of Service via multi-packet uploads in UDP.
Scope: local
bookworm: resolved (fixed in 1.6.8+dfsg-1)
bullseye: resolved (fixed in 1.6.8+dfsg-1)
forky: resolved (fixed in 1.6.8+dfsg-1)
sid: resolved (fixed in 1.6.8+dfsg-1)
trixie: resolved (fixed in 1.6.8+dfsg-1)
GHSA
GHSA-x6px-h85m-3m6v: memcached 1
ghsa_unreviewed·2023-08-22
CVE-2022-48571 [HIGH] CWE-400 GHSA-x6px-h85m-3m6v: memcached 1
memcached 1.6.7 allows a Denial of Service via multi-packet uploads in UDP.
OSV
CVE-2022-48571: memcached 1
osv·2023-08-22·CVSS 7.5
CVE-2022-48571 [HIGH] CVE-2022-48571: memcached 1
memcached 1.6.7 allows a Denial of Service via multi-packet uploads in UDP.
No detection rules found.
No public exploits indexed.
https://github.com/memcached/memcached/commit/6b319c8c7a29e9c353dec83dc92f01905f6c8966https://lists.debian.org/debian-lts-announce/2023/09/msg00004.htmlhttps://github.com/memcached/memcached/commit/6b319c8c7a29e9c353dec83dc92f01905f6c8966https://lists.debian.org/debian-lts-announce/2023/09/msg00004.html
2023-08-22
Published