openwrt ▾
›
master ▾
›
vulnerability
›
CVE-2026-47784
Component Overview
Vulnerability Overview
Name
CVE-2026-47784
Source
NVD (
link
)
Debian (
link
)
Description
In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass.
CWEs
CWE-208
Published Date
May 20, 2026
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/memcached/memcached/commit/d13f282b4bce33a9c33b8a1bbf07f12114160fed
Patch
https://github.com/memcached/memcached/compare/1.6.41...1.6.42
Release Notes
https://github.com/memcached/memcached/wiki/ReleaseNotes1642
Release Notes
Analysis
#
Affected Component
Analysis
memcached
Exploitable
Vulnerability Ratings
#
8.1
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
memcached
buildroot
2025.02.x
1.6.42
Not Affected
memcached
buildroot
master
1.6.42
Not Affected
memcached
yocto
kirkstone
1.6.15
Exploitable
memcached
yocto
master
1.6.42
Not Affected
memcached
yocto
scarthgap
1.6.17
Exploitable