# UNDF: UNDF-2026-000000169 # memcached CWE-407 Scan — CLEAN (deeper scan) **Date:** 2026-03-27 **Repo:** https://github.com/memcached/memcached **Scan scope:** `items.c`, `thread.c`, `slabs.c`, `proto_text.c`, `proto_proxy.c`, `proxy_lua.c`, `assoc.c` ## Findings No new CWE-407 defects found beyond the existing `memcached-0001` patch. ### Candidates examined | File | Location | Pattern | Verdict | |------|----------|---------|---------| | `slabs.c` | `slabs_clsid()` | `while (size > slabclass[res].size)` linear scan — **already patched** as `0001-slabs-clsid-binary-search.patch` | PATCHED (0001) | | `items.c` | `lru_pull_tail()` | `for (; tries > 0 && search != NULL; tries--, search=next_it)` — bounded to 5 tries max, not scaling with N | CLEAN (bounded) | | `assoc.c` | `_hashitem_before()` | `while (*pos && memcmp(...))` — hash bucket chain traversal; expected hash collision resolution, not per-request linear scan of the full table | CLEAN (hash bucket) | | `proto_text.c` | `process_command_ascii()` | Command dispatch uses `switch(pr.command)` on a pre-parsed enum — O(1) | CLEAN | | `proto_text.c` | `process_stat_command()` | Stat subcommands dispatched via `else if (strncmp(...))` chain — bounded to ~10 subcommands, constant factor | CLEAN (bounded) | | `memcached.c` | restart config loading | `while (opts[type] != NULL && strcmp(key, opts[type]) != 0)` — linear scan through restart config key table; startup path only, not per-request | CLEAN (startup-only) | | `proxy_lua.c` | `_mcplib_backend_checkcache()` | `strncmp` for backend label match — called once per pool entry during configuration, not per-request routing | CLEAN (config-time) | | `thread.c` | connection queue | Linked-list queue operations using `STAILQ_*` macros — O(1) enqueue/dequeue, no membership test | CLEAN | ## Summary The command dispatch path is O(1) via switch/enum. The only true linear scan on a hot path was `slabs_clsid()`, already patched in `0001`. All other loops in the requested files are either startup-time, bounded by small constants, or are expected hash-collision resolution in a proper hash table.