This bug was fixed in the package memcached - 1.6.40-1ubuntu0.2

---------------
memcached (1.6.40-1ubuntu0.2) resolute-security; urgency=medium

  * SECURITY UPDATE: out-of-bounds heap write in the LRU crawler dump path
    when an idle client stalls reading a dump (LP: #2161693):
    - 
debian/patches/lp2161693-0-fix-lru-crawler-buffer-overflow-on-idle-client.patch:
      backport 7eeac6e9, retry on poll() timeout instead of a false flush.
    - debian/patches/lp2161693-1-fix-lru-crawler-unlock-of-unlocked-mutex.patch:
      backport ea35f44, lock lru_locks[i] before lru_crawler_class_done().

 -- Seyeong Kim <[email protected]>  Fri, 24 Jul 2026 03:10:56
+0000

** Changed in: memcached (Ubuntu Resolute)
       Status: Confirmed => Fix Released

** Changed in: memcached (Ubuntu Noble)
       Status: Confirmed => Fix Released

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2161693

Title:
  memcached: heap buffer overflow in LRU crawler dump (lru_crawler
  metadump) on an idle client

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/memcached/+bug/2161693/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to