Input validation error in memcached - CVE-2022-48571
Published: September 11, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input when processing multi-packet uploads in UDP within the resp_has_stack() function in memcached.c. A remote attacker can send specially crafted packets to the application and perform a denial of service (DoS) attack.
Affected software
Ubuntu
memcached (Ubuntu package)
How to mitigate CVE-2022-48571
memcached (Ubuntu package) - addressed in versions Ubuntu Pro, 1.5.22-2ubuntu0.3