CVE-2023-46853
published 2023-10-27CVE-2023-46853: In Memcached before 1.6.22, an off-by-one error exists when processing proxy requests in proxy mode, if \n is used instead of \r\n.
PriorityP344critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.76%
51.3th percentile
In Memcached before 1.6.22, an off-by-one error exists when processing proxy requests in proxy mode, if \n is used instead of \r\n.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | memcached | < memcached 1.6.22-1 (forky) | memcached 1.6.22-1 (forky) |
| memcached | memcached | < 1.6.22 | 1.6.22 |
| memcached | memcached | >= 0 < 1.6.22-1 | 1.6.22-1 |
| memcached | memcached | >= 0 < 1.6.22-1 | 1.6.22-1 |
| memcached | memcached | >= 0 < 1.6.14-1ubuntu0.1 | 1.6.14-1ubuntu0.1 |
| msrc | azl3_memcached_1.6.21-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_memcached_1.6.27-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_memcached_1.6.22-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_msrc9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Memcached vulnerabilities
vendor_ubuntu·2023-11-13·CVSS 7.5
CVE-2023-46852 [HIGH] Memcached vulnerabilities
Title: Memcached vulnerabilities
Summary: Several security issues were fixed in memcached.
It was discovered that Memcached incorrectly handled certain multiget
requests in proxy mode. A remote attacker could use this issue to cause
Memcached to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2023-46852)
It was discovered that Memcached incorrectly handled certain proxy requests
in proxy mode. A remote attacker could use this issue to cause Memcached to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2023-46853)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
memcached: off-by-one error when processing proxy requests in proxy mode
vendor_redhat·2023-10-27·CVSS 9.8
CVE-2023-46853 [CRITICAL] CWE-193 memcached: off-by-one error when processing proxy requests in proxy mode
memcached: off-by-one error when processing proxy requests in proxy mode
In Memcached before 1.6.22, an off-by-one error exists when processing proxy requests in proxy mode, if \n is used instead of \r\n.
An off-by-one error was found in Memcached. This issue occurs when processing proxy requests in proxy mode if \n is used instead of \r\n.
Statement: Proxy mode in memcached was introduced in 1.6.13, so Red Hat Enterprise Linux is not affected by this CVE.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: memcached (Red Hat Enterprise Linux 6) - Not affected
Package: memcached (Red
Microsoft
In Memcached before 1.6.22 an off-by-one error exists when processing proxy requests in proxy mode if \n is used instead of \r\n.
vendor_msrc·2023-10-10·CVSS 9.8
CVE-2023-46853 [CRITICAL] CWE-193 In Memcached before 1.6.22 an off-by-one error exists when processing proxy requests in proxy mode if \n is used instead of \r\n.
In Memcached before 1.6.22 an off-by-one error exists when processing proxy requests in proxy mode if \n is used instead of \r\n.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Customer Action
Debian
CVE-2023-46853: memcached - In Memcached before 1.6.22, an off-by-one error exists when processing proxy req...
vendor_debian·2023·CVSS 9.8
CVE-2023-46853 [CRITICAL] CVE-2023-46853: memcached - In Memcached before 1.6.22, an off-by-one error exists when processing proxy req...
In Memcached before 1.6.22, an off-by-one error exists when processing proxy requests in proxy mode, if \n is used instead of \r\n.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.6.22-1)
sid: resolved (fixed in 1.6.22-1)
trixie: resolved (fixed in 1.6.22-1)
OSV
memcached vulnerabilities
osv·2023-11-13·CVSS 7.5
CVE-2023-46852 [HIGH] memcached vulnerabilities
memcached vulnerabilities
It was discovered that Memcached incorrectly handled certain multiget
requests in proxy mode. A remote attacker could use this issue to cause
Memcached to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2023-46852)
It was discovered that Memcached incorrectly handled certain proxy requests
in proxy mode. A remote attacker could use this issue to cause Memcached to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2023-46853)
OSV
CVE-2023-46853: In Memcached before 1
osv·2023-10-27·CVSS 9.8
CVE-2023-46853 [CRITICAL] CVE-2023-46853: In Memcached before 1
In Memcached before 1.6.22, an off-by-one error exists when processing proxy requests in proxy mode, if \n is used instead of \r\n.
GHSA
GHSA-jr2m-hrp3-3wj4: In Memcached before 1
ghsa_unreviewed·2023-10-27
CVE-2023-46853 [CRITICAL] CWE-193 GHSA-jr2m-hrp3-3wj4: In Memcached before 1
In Memcached before 1.6.22, an off-by-one error exists when processing proxy requests in proxy mode, if \n is used instead of \r\n.
No detection rules found.
No public exploits indexed.
2023-10-27
Published