CVE-2022-48571
Memcached vulnerability analysis and mitigation

Overview

Memcached version 1.6.7 was discovered to contain a Denial of Service vulnerability (CVE-2022-48571) that occurs when handling multi-packet uploads in UDP mode. The vulnerability was discovered in July 2023 and affects the high-performance memory object caching system (CVE Details, Debian Security).

Technical details

The vulnerability stems from incorrect handling of multi-packet uploads in UDP mode. When receiving multi-packet requests, the system attempts to write an error message in response, but due to an uninitialized mc_resp object, it leads to a null reference crash. The vulnerability has been assigned a CVSS 3.1 base score of 7.5 (High), with attack vector being Network, attack complexity Low, and requiring no privileges or user interaction (Ubuntu Security).

Impact

The vulnerability can be exploited to cause a Denial of Service condition in affected Memcached installations. However, deployments that only use TCP are likely unaffected by this issue (Debian LTS).

Mitigation and workarounds

The vulnerability has been fixed in multiple versions across different distributions. Ubuntu has released fixes for versions 20.04 LTS (1.5.22-2ubuntu0.3), 18.04 LTS (1.5.6-0ubuntu1.2+esm1), and 16.04 LTS (1.4.25-2ubuntu1.5+esm1). Debian has addressed the issue in version 1.5.6-1.1+deb10u1 for Debian 10 buster. The fix involves dropping multi-packet requests quietly instead of attempting to write an error message (Ubuntu Notice, GitHub Commit).

Additional resources


SourceThis report was generated using AI

Related Memcached vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-46853CRITICAL9.8
  • MemcachedMemcached
  • cpe:2.3:a:memcached:memcached
NoYesOct 27, 2023
CVE-2023-46852HIGH7.5
  • MemcachedMemcached
  • memcached
NoYesOct 27, 2023
CVE-2022-48571HIGH7.5
  • MemcachedMemcached
  • memcached
NoYesAug 22, 2023
CVE-2020-22570HIGH7.5
  • MemcachedMemcached
  • cpe:2.3:a:memcached:memcached
NoYesAug 22, 2023
CVE-2021-37519MEDIUM5.5
  • MemcachedMemcached
  • memcached
NoYesFeb 03, 2023

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management