Fix CVE-2026-47783: SASL timing side-channel in memcached

Backport upstream fix for CVE-2026-47783, a timing side-channel
vulnerability in memcached's SASL password database authentication.
The patch modifies sasl_defs.c to zero the buffer before each fgets
call, use constant-time safe_memcmp() for username and password
comparisons, and remove the early loop break so the entire password
file is always scanned.

CVE: CVE-2026-47783
Upstream patches:
 - d13f282b4b.patch
Resolves: RHEL-179094

This commit was backported by Ymir, a Red Hat Enterprise Linux software maintenance AI agent.

Assisted-by: Ymir
This commit is contained in:
RHEL Packaging Agent 2026-07-14 13:28:38 +00:00
parent 671dceea6a
commit e99e7308eb
2 changed files with 65 additions and 1 deletions

View File

@ -0,0 +1,56 @@
From e42b3147d82a1dd15e8a1227ed1f41f3f1a63077 Mon Sep 17 00:00:00 2001
From: Sarthak Munshi <sarthakmunshi@gmail.com>
Date: Sat, 21 Mar 2026 15:20:25 -0700
Subject: [PATCH] Fix timing side-channel in SASL password database
authentication
sasl_server_userdb_checkpass() broke out of the password file loop
early when a valid username was found, creating a measurable timing
difference between valid and invalid usernames. Additionally, the
password comparison used memcmp() which returns early on the first
differing byte, potentially leaking password bytes via timing analysis.
Fix both issues with minimal changes per reviewer feedback:
- Clear buffer to zero before each fgets so comparisons past the
stored password hit known zero bytes
- Use safe_memcmp() for both username and password comparisons
(constant-time, volatile-qualified)
- Remove the early break so the entire file is always scanned
---
sasl_defs.c | 21 ++++++++++-----------
1 file changed, 10 insertions(+), 11 deletions(-)
diff --git a/sasl_defs.c b/sasl_defs.c
index e73a570..98a1f75 100644
--- a/sasl_defs.c
+++ b/sasl_defs.c
@@ -71,19 +71,18 @@ static int sasl_server_userdb_checkpass(sasl_conn_t *conn,
char buffer[MAX_ENTRY_LEN];
bool ok = false;
- while ((fgets(buffer, sizeof(buffer), pwfile)) != NULL) {
- if (memcmp(user, buffer, unmlen) == 0 && buffer[unmlen] == ':') {
- /* This is the correct user */
- ++unmlen;
- if (memcmp(pass, buffer + unmlen, passlen) == 0 &&
- (buffer[unmlen + passlen] == ':' || /* Additional tokens */
- buffer[unmlen + passlen] == '\n' || /* end of line */
- buffer[unmlen + passlen] == '\r'|| /* dos format? */
- buffer[unmlen + passlen] == '\0')) { /* line truncated */
+ while (1) {
+ memset(buffer, 0, sizeof(buffer));
+ if (fgets(buffer, sizeof(buffer), pwfile) == NULL)
+ break;
+ if (safe_memcmp(user, buffer, unmlen) && buffer[unmlen] == ':') {
+ if (safe_memcmp(pass, buffer + unmlen + 1, passlen) &&
+ (buffer[unmlen + 1 + passlen] == ':' ||
+ buffer[unmlen + 1 + passlen] == '\n' ||
+ buffer[unmlen + 1 + passlen] == '\r' ||
+ buffer[unmlen + 1 + passlen] == '\0')) {
ok = true;
}
-
- break;
}
}
(void)fclose(pwfile);

View File

@ -12,7 +12,7 @@
Name: memcached
Version: 1.6.9
Release: 7%{?dist}
Release: 8%{?dist}
Epoch: 0
Summary: High Performance, Distributed Memory Object Cache
@ -25,6 +25,9 @@ Source2: https://releases.pagure.org/memcached-selinux/memcached-selinux-
Source3: memcached.conf
Patch1: memcached-unit.patch
# https://issues.redhat.com/browse/RHEL-179094
# https://github.com/memcached/memcached/commit/d13f282b4bce33a9c33b8a1bbf07f12114160fed
Patch2: memcached-1.6.9-CVE-2026-47783.patch
BuildRequires: make
BuildRequires: gcc libevent-devel systemd
@ -71,6 +74,7 @@ optimised for use with this version of memcached.
# and SELinux policy sources into memcached-selinux-X.X
%setup -q -b 2
%patch1 -p1 -b .unit
%patch2 -p1 -b .CVE-2026-47783
%build
%configure \
@ -174,6 +178,10 @@ fi
%license ../%{selinuxmoduledir}/COPYING
%changelog
* Tue Jul 14 2026 RHEL Packaging Agent <redhat-ymir-agent@redhat.com> - 0:1.6.9-8
- Fix timing side-channel in SASL password database authentication
- Resolves: RHEL-179094
* Wed Jun 15 2022 Tomas Korbar <tkorbar@redhat.com> - 0:1.6.9-7
- Use systemd-users
- Resolves: rhbz#2095432