CVE-2018-1000127
memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free() that can result in data corruption and deadlocks due to items existing in hash table being reused from free list.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.24%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free() that can result in data corruption and deadlocks due to items existing in hash table being reused from free list. This attack appear to be exploitable via network connectivity to the memcached service. This vulnerability appears to have been fixed in 1.4.37 and later.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 2.24% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-190, CWE-667
- Affected
- memcached/memcached · debian/debian linux · canonical/ubuntu linux · redhat/openstack
- Source
- cve@mitre.org
References
- https://access.redhat.com/errata/RHSA-2018:2290Third Party Advisory
- https://github.com/memcached/memcached/commit/a8c4a82787b8b6c256d61bd5c42fb7f92d1bae00Patch, Third Party Advisory
- https://github.com/memcached/memcached/issues/271Third Party Advisory
- https://github.com/memcached/memcached/wiki/ReleaseNotes1437Release Notes, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/03/msg00031.htmlMailing List, Third Party Advisory
- https://usn.ubuntu.com/3601-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4218Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2290Third Party Advisory
- https://github.com/memcached/memcached/commit/a8c4a82787b8b6c256d61bd5c42fb7f92d1bae00Patch, Third Party Advisory
- https://github.com/memcached/memcached/issues/271Third Party Advisory
- https://github.com/memcached/memcached/wiki/ReleaseNotes1437Release Notes, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/03/msg00031.htmlMailing List, Third Party Advisory
- https://usn.ubuntu.com/3601-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4218Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.