High Performance, Distributed Memory Object Cache
Go to file
RHEL Packaging Agent 468226af29 Fix CVE-2026-47783: SASL timing side-channel in memcached
Backport upstream fix for CVE-2026-47783 to memcached 1.5.22.
The patch replaces memcmp-based comparisons in sasl_defs.c with
constant-time safe_memcmp() calls and removes early loop exit,
preventing timing side-channel attacks against SASL password
database authentication.

CVE: CVE-2026-47783
Upstream patches:
 - d13f282b4b.patch
Resolves: RHEL-179088

This commit was backported by Ymir, a Red Hat Enterprise Linux software maintenance AI agent.

Assisted-by: Ymir
2026-06-12 07:59:58 +00:00
.fmf Fix testing metadata 2026-06-11 14:58:46 +02:00
.gitignore Import rpm: c8s 2023-02-27 14:21:47 -05:00
ci.fmf Fix testing metadata 2026-06-11 14:58:46 +02:00
gating.yaml Fix testing metadata 2026-06-11 14:58:46 +02:00
memcached-CVE-2026-47783.patch Fix CVE-2026-47783: SASL timing side-channel in memcached 2026-06-12 07:59:58 +00:00
memcached-fix-rejconn-counting.patch Auto sync2gitlab import of memcached-1.5.22-2.el8.src.rpm 2022-05-26 11:21:22 -04:00
memcached-issue685.patch Auto sync2gitlab import of memcached-1.5.22-2.el8.src.rpm 2022-05-26 11:21:22 -04:00
memcached-low-conns-segfault.patch Auto sync2gitlab import of memcached-1.5.22-2.el8.src.rpm 2022-05-26 11:21:22 -04:00
memcached-metaget-errstr-init.patch Auto sync2gitlab import of memcached-1.5.22-2.el8.src.rpm 2022-05-26 11:21:22 -04:00
memcached-restart-corrupted.patch Auto sync2gitlab import of memcached-1.5.22-2.el8.src.rpm 2022-05-26 11:21:22 -04:00
memcached-restart-del-items-fail.patch Auto sync2gitlab import of memcached-1.5.22-2.el8.src.rpm 2022-05-26 11:21:22 -04:00
memcached-restart-double-free.patch Auto sync2gitlab import of memcached-1.5.22-2.el8.src.rpm 2022-05-26 11:21:22 -04:00
memcached-restart-shutdown-segfault.patch Auto sync2gitlab import of memcached-1.5.22-2.el8.src.rpm 2022-05-26 11:21:22 -04:00
memcached-sasl-config.patch Auto sync2gitlab import of memcached-1.5.22-2.el8.src.rpm 2022-05-26 11:21:22 -04:00
memcached-sig-handler.patch Auto sync2gitlab import of memcached-1.5.22-2.el8.src.rpm 2022-05-26 11:21:22 -04:00
memcached-stats.patch Auto sync2gitlab import of memcached-1.5.22-2.el8.src.rpm 2022-05-26 11:21:22 -04:00
memcached-test-cache-dump.patch Auto sync2gitlab import of memcached-1.5.22-2.el8.src.rpm 2022-05-26 11:21:22 -04:00
memcached-tls-crt-refresh-crash.patch Auto sync2gitlab import of memcached-1.5.22-2.el8.src.rpm 2022-05-26 11:21:22 -04:00
memcached-tls-hand-errs.patch Auto sync2gitlab import of memcached-1.5.22-2.el8.src.rpm 2022-05-26 11:21:22 -04:00
memcached-unit.patch Auto sync2gitlab import of memcached-1.5.22-2.el8.src.rpm 2022-05-26 11:21:22 -04:00
memcached.spec Fix CVE-2026-47783: SASL timing side-channel in memcached 2026-06-12 07:59:58 +00:00
memcached.sysconfig Auto sync2gitlab import of memcached-1.5.22-2.el8.src.rpm 2022-05-26 11:21:22 -04:00
plans.fmf Fix testing metadata 2026-06-11 14:58:46 +02:00
sources Auto sync2gitlab import of memcached-1.5.22-2.el8.src.rpm 2022-05-26 11:21:22 -04:00