amazon-linux-2023 icon indicating copy to clipboard operation
amazon-linux-2023 copied to clipboard

[Package Upgrade Request] - memcached

Open Jetski5822 opened this issue 6 months ago • 5 comments

What package is missing from Amazon Linux 2023? Please describe and include package name.

The memcached package is not missing from Amazon Linux 2023, but it requires an update to the latest stable version.

Is this an update to existing package or new package request?

This is an update to an existing package.

Is this package available in Amazon Linux 2? If it is available via external sources such as EPEL, please specify.

memcached is available in Fedora and other distributions. For example: https://packages.fedoraproject.org/pkgs/memcached/memcached/

The latest version from the memcached website https://memcached.org/downloads is 1.6.38

Any additional information you'd like to include. (use-cases, etc)

The latest versions of Memcached contain important performance improvements, bug fixes, and security patches. Reference: https://memcached.org/ and https://github.com/memcached/memcached/wiki/ReleaseNotes

Keeping this package up-to-date ensures better performance, protocol support, and compatibility with modern client libraries.

Jetski5822 avatar Jun 24 '25 13:06 Jetski5822

@Jetski5822 Thank you for the request, the Amazon Linux Team is taking a look.

joeysk2012 avatar Jun 24 '25 20:06 joeysk2012

The current version that is shipped with AL2023 is memcached-1.6.22-2.amzn2023.0.1 I doubt a bit about the claim that the latest version contains fixes for some security issues.

The latest known CVE was found in 2023:

  • https://www.cve.org/CVERecord/SearchResults?query=memcached
  • https://www.cve.org/CVERecord?id=CVE-2023-46853

...and it was fixed in the version 1.6.22, which we actually ship.

I just wanted to make it clear and stress that at this moment, the is NO known CVE in the version that is shipped in AL2023. In other words, your request is related to adding new features, right?

It would be very appreciated if you, @Jetski5822, could let us know what exact feature or a bug fix in the latest version you are looking for? Thanks!

alexey-tsvetnov avatar Jun 24 '25 20:06 alexey-tsvetnov

Hey @alexey-tsvetnov — thanks for the super quick reply!

I'm particularly interested in the TLS-related fixes introduced in the following releases:

1.6.30 Release Notes

1.6.31 Release Notes

Additionally, the layered security enhancements in 1.6.37 are important to me, as I operate in a multi-tenant environment.

Lastly, there are some valuable memory-related bug fixes in 1.6.38 that I'd like to test out.

Thanks again!

Jetski5822 avatar Jun 24 '25 22:06 Jetski5822

@Jetski5822 The memcached package has been upgraded to version 1.6.38 in Amazon Linux 2023. This upgrade includes:

  • TLS-related improvements from versions 1.6.30 and 1.6.31
  • Enhanced layered security features from version 1.6.37
  • Memory-related bug fixes from version 1.6.38

prachial avatar Aug 21 '25 18:08 prachial

It's been released in 2023.8.20250808

alexey-tsvetnov avatar Aug 21 '25 19:08 alexey-tsvetnov