libmemcached could return data for a previously requested key, if that previous request timed out due to a low POLL_TIMEOUT. GitHub security advisory: https://github.com/awesomized/libmemcached/security/advisories/GHSA-wwmh-39wj-fx59 Upstream issue & fix: https://github.com/php-memcached-dev/php-memcached/issues/531 https://github.com/awesomized/libmemcached/commit/48dcc61a
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2023-27478