Fedora Account System
Red Hat Associate
Red Hat Customer
In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:27842 https://access.redhat.com/errata/RHSA-2026:27842
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:27862 https://access.redhat.com/errata/RHSA-2026:27862