Skip to content

Commit f58aba8

Browse files
simiRubySec CI
authored andcommitted
Updated advisory posts against rubysec/ruby-advisory-db@960b055
1 parent 87eb657 commit f58aba8

6 files changed

Lines changed: 376 additions & 0 deletions
Lines changed: 51 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,51 @@
1+
---
2+
layout: advisory
3+
title: 'GHSA-3553-vcg5-72jw (dalli): Unbounded decompression and reply sizes allow
4+
memory exhaustion'
5+
comments: false
6+
categories:
7+
- dalli
8+
advisory:
9+
gem: dalli
10+
ghsa: 3553-vcg5-72jw
11+
url: https://github.com/petergoldstein/dalli/security/advisories/GHSA-3553-vcg5-72jw
12+
title: Unbounded decompression and reply sizes allow memory exhaustion
13+
date: 2026-10-05
14+
description: |-
15+
1. Values flagged as compressed were inflated with no size limit. A
16+
~130 KB stored item expands to 128 MB on read (about 1000:1),
17+
regardless of the client's `compress` or `serializer` settings.
18+
2. The size in a reply (a meta `VA <size>`, or a binary body length) was
19+
used to read or buffer that many bytes, so a hostile or compromised
20+
server could make the client allocate gigabytes.
21+
22+
Exploiting either requires write access to the memcached instance (a
23+
shared or exposed instance, another tenant), or a malicious server or
24+
proxy. Patched versions add a `decompressed_max_bytes` option (default
25+
128 MiB) and reject reply sizes over 1 GiB.
26+
patched_versions:
27+
- "~> 3.2.12"
28+
- "~> 4.3.6"
29+
- "~> 5.0.9"
30+
- "~> 5.1.3"
31+
- ">= 5.2.1"
32+
related:
33+
url:
34+
- https://github.com/petergoldstein/dalli/security/advisories/GHSA-3553-vcg5-72jw
35+
- https://github.com/petergoldstein/dalli/commit/39d2f72
36+
- https://rubygems.org/gems/dalli/versions/5.2.1
37+
- https://github.com/petergoldstein/dalli/releases/tag/v5.2.1
38+
- https://rubygems.org/gems/dalli/versions/5.1.3
39+
- https://github.com/petergoldstein/dalli/releases/tag/v5.1.3
40+
- https://rubygems.org/gems/dalli/versions/5.0.9
41+
- https://github.com/petergoldstein/dalli/releases/tag/v5.0.9
42+
- https://rubygems.org/gems/dalli/versions/4.3.6
43+
- https://github.com/petergoldstein/dalli/releases/tag/v4.3.6
44+
- https://rubygems.org/gems/dalli/versions/3.2.12
45+
- https://github.com/petergoldstein/dalli/releases/tag/v3.2.12
46+
notes: |
47+
- No CVE in GHSA.
48+
- "A CVE has been requested through GitHub but not yet
49+
assigned, so the entry has no cve: field."
50+
- No CVSS score in GHSA; GitHub severity is medium.
51+
---
Lines changed: 59 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,59 @@
1+
---
2+
layout: advisory
3+
title: 'GHSA-4qp6-2jcr-596v (dalli): Routing tokens can inject meta protocol flags,
4+
and failed requests can retry forever'
5+
comments: false
6+
categories:
7+
- dalli
8+
advisory:
9+
gem: dalli
10+
ghsa: 4qp6-2jcr-596v
11+
url: https://github.com/petergoldstein/dalli/security/advisories/GHSA-4qp6-2jcr-596v
12+
title: Routing tokens can inject meta protocol flags, and failed requests can retry
13+
forever
14+
date: 2026-10-05
15+
description: |-
16+
1. `p_token` and `l_token` were checked only for CR, LF and NUL. A token
17+
containing spaces added arbitrary meta flags to the command: for
18+
example changing an item's TTL on a read, creating stub items on a
19+
miss, turning a delete into a stale tombstone, choosing `incr`'s
20+
initial value, or reading a different key. Affects 5.1.0 and later.
21+
2. Failed requests were retried without a limit. Each retry reconnected
22+
successfully, which reset the failure count, so `socket_max_failures`
23+
was never reached and requests to a server that accepts connections
24+
but never replies (or drops the connection on a request) hung
25+
forever. Affects all versions.
26+
3. Errors raised by application code inside a `get_multi` block
27+
(`Errno::*`, `Timeout::Error`) were treated as socket errors and
28+
retried the whole `get_multi`, causing duplicate yields, swallowed
29+
exceptions, or an endless loop. Affects 4.x and 5.x.
30+
31+
### Workarounds
32+
33+
Don't pass untrusted input as a routing token.
34+
patched_versions:
35+
- "~> 3.2.12"
36+
- "~> 4.3.6"
37+
- "~> 5.0.9"
38+
- "~> 5.1.3"
39+
- ">= 5.2.1"
40+
related:
41+
url:
42+
- https://github.com/petergoldstein/dalli/security/advisories/GHSA-4qp6-2jcr-596v
43+
- https://github.com/petergoldstein/dalli/commit/f8f7a21
44+
- https://rubygems.org/gems/dalli/versions/5.2.1
45+
- https://github.com/petergoldstein/dalli/releases/tag/v5.2.1
46+
- https://rubygems.org/gems/dalli/versions/5.1.3
47+
- https://github.com/petergoldstein/dalli/releases/tag/v5.1.3
48+
- https://rubygems.org/gems/dalli/versions/5.0.9
49+
- https://github.com/petergoldstein/dalli/releases/tag/v5.0.9
50+
- https://rubygems.org/gems/dalli/versions/4.3.6
51+
- https://github.com/petergoldstein/dalli/releases/tag/v4.3.6
52+
- https://rubygems.org/gems/dalli/versions/3.2.12
53+
- https://github.com/petergoldstein/dalli/releases/tag/v3.2.12
54+
notes: |
55+
- No CVE in GHSA.
56+
- "A CVE has been requested through GitHub but not yet
57+
assigned, so the entry has no cve: field."
58+
- No CVSS score in GHSA; GitHub severity is medium.
59+
---
Lines changed: 57 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,57 @@
1+
---
2+
layout: advisory
3+
title: 'GHSA-m252-9cgf-vx2w (dalli): With a namespace, a retried request reads or
4+
writes a different key'
5+
comments: false
6+
categories:
7+
- dalli
8+
advisory:
9+
gem: dalli
10+
ghsa: m252-9cgf-vx2w
11+
url: https://github.com/petergoldstein/dalli/security/advisories/GHSA-m252-9cgf-vx2w
12+
title: With a namespace, a retried request reads or writes a different key
13+
date: 2026-10-05
14+
description: |-
15+
When a client is configured with a `namespace`, a request that hits a
16+
transient network error (a timeout, or a connection closed by memcached
17+
or a proxy, such as stale connections after a memcached restart) was
18+
retried with the namespace applied a second time, so `app:x` became
19+
`app:app:x`. A retried read could return a different key's value, and a
20+
retried write could overwrite a different key. Where cache keys include
21+
user input, a user who can choose a key of the form `app:<something>`
22+
can arrange for another user's retried read to return attacker-chosen
23+
data.
24+
25+
Affected: every single-key operation since 5.0.3, single-server
26+
`get_multi` since 5.1.0, and `get_with_metadata` and `fetch_with_lock`
27+
since 4.1.0. Clients without a namespace are not affected, and 3.2.x is
28+
not affected.
29+
30+
### Workarounds
31+
32+
Don't configure a `namespace`; prefix keys in application code instead.
33+
unaffected_versions:
34+
- "< 4.1.0"
35+
patched_versions:
36+
- "~> 4.3.7"
37+
- "~> 5.0.10"
38+
- "~> 5.1.4"
39+
- ">= 5.2.2"
40+
related:
41+
url:
42+
- https://github.com/petergoldstein/dalli/security/advisories/GHSA-m252-9cgf-vx2w
43+
- https://github.com/petergoldstein/dalli/commit/61a9813
44+
- https://rubygems.org/gems/dalli/versions/5.2.2
45+
- https://github.com/petergoldstein/dalli/releases/tag/v5.2.2
46+
- https://rubygems.org/gems/dalli/versions/5.1.4
47+
- https://github.com/petergoldstein/dalli/releases/tag/v5.1.4
48+
- https://rubygems.org/gems/dalli/versions/5.0.10
49+
- https://github.com/petergoldstein/dalli/releases/tag/v5.0.10
50+
- https://rubygems.org/gems/dalli/versions/4.3.7
51+
- https://github.com/petergoldstein/dalli/releases/tag/v4.3.7
52+
notes: |
53+
- No CVE in GHSA.
54+
- "A CVE has been requested through GitHub but not yet
55+
assigned, so the entry has no cve: field."
56+
- No CVSS score in GHSA; GitHub severity is high.
57+
---
Lines changed: 63 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,63 @@
1+
---
2+
layout: advisory
3+
title: 'GHSA-p6pm-ch9v-44vx (dalli): Pipelined get_multi can return another key''s
4+
value after an error reply'
5+
comments: false
6+
categories:
7+
- dalli
8+
advisory:
9+
gem: dalli
10+
ghsa: p6pm-ch9v-44vx
11+
url: https://github.com/petergoldstein/dalli/security/advisories/GHSA-p6pm-ch9v-44vx
12+
title: Pipelined get_multi can return another key's value after an error reply
13+
date: 2026-10-05
14+
description: |-
15+
Dalli's pipelined reply parser treated any reply line without a value
16+
body (for example `CLIENT_ERROR` or `SERVER_ERROR`) as the `MN` that
17+
ends the batch. It stopped reading that server's replies and left the
18+
rest on the connection, where later commands read them as their own
19+
replies, so a later `get` could return a different key's value.
20+
21+
memcached answers `CLIENT_ERROR` for a key over 250 bytes on the wire.
22+
Dalli checked key length in characters, before base64-encoding keys
23+
that need it, so a key of under 250 characters could still be too long.
24+
If any part of a cache key comes from user input, a user can trigger
25+
this and, in an application that caches per-user data, see another
26+
user's data. Affects multi-server `get_multi` (including Rails
27+
`read_multi`), `get_multi` with a block, and `get_multi_cas`, with the
28+
meta protocol (3.2.0 and later; the default since 5.0.0).
29+
30+
With the binary protocol (the default before 5.0), the same over-long
31+
key made memcached drop the connection, and `get` or `get_multi` with
32+
it retried forever, so a user-supplied key could hang requests.
33+
34+
### Workarounds
35+
36+
Keep user-controlled cache keys well under 250 bytes, for example by
37+
hashing them.
38+
patched_versions:
39+
- "~> 3.2.12"
40+
- "~> 4.3.6"
41+
- "~> 5.0.9"
42+
- "~> 5.1.3"
43+
- ">= 5.2.1"
44+
related:
45+
url:
46+
- https://github.com/petergoldstein/dalli/security/advisories/GHSA-p6pm-ch9v-44vx
47+
- https://github.com/petergoldstein/dalli/commit/e35c7ad
48+
- https://rubygems.org/gems/dalli/versions/5.2.1
49+
- https://github.com/petergoldstein/dalli/releases/tag/v5.2.1
50+
- https://rubygems.org/gems/dalli/versions/5.1.3
51+
- https://github.com/petergoldstein/dalli/releases/tag/v5.1.3
52+
- https://rubygems.org/gems/dalli/versions/5.0.9
53+
- https://github.com/petergoldstein/dalli/releases/tag/v5.0.9
54+
- https://rubygems.org/gems/dalli/versions/4.3.6
55+
- https://github.com/petergoldstein/dalli/releases/tag/v4.3.6
56+
- https://rubygems.org/gems/dalli/versions/3.2.12
57+
- https://github.com/petergoldstein/dalli/releases/tag/v3.2.12
58+
notes: |
59+
- No CVE in GHSA.
60+
- "A CVE has been requested through GitHub but not yet
61+
assigned, so the entry has no cve: field."
62+
- No CVSS score in GHSA; GitHub severity is high.
63+
---
Lines changed: 68 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,68 @@
1+
---
2+
layout: advisory
3+
title: 'GHSA-w39f-xq2m-4g8x (dalli): Forking can resend buffered memcached requests
4+
and desynchronize the parent''s connection'
5+
comments: false
6+
categories:
7+
- dalli
8+
advisory:
9+
gem: dalli
10+
ghsa: w39f-xq2m-4g8x
11+
url: https://github.com/petergoldstein/dalli/security/advisories/GHSA-w39f-xq2m-4g8x
12+
title: Forking can resend buffered memcached requests and desynchronize the parent's
13+
connection
14+
date: 2026-10-05
15+
description: |-
16+
Dalli buffered request bytes in Ruby's IO write buffer, and quiet
17+
(`multi`) blocks don't flush until they end. When the process forks,
18+
the child inherits the buffer, and Ruby flushes it when the child closes
19+
or finalizes the socket, even if the child never uses Dalli, so the
20+
request is sent twice: a buffered write is applied twice, or a buffered
21+
non-quiet request leaves the parent's connection off by one reply, so
22+
later reads return the previous key's value. Affects 4.2.0 and later.
23+
24+
With TLS, the child's close sends close_notify on the shared connection
25+
and tears down the parent's session. Affects all versions with TLS.
26+
27+
Applications that fork while threads use a shared client are affected
28+
(pre-forking servers, job runners).
29+
30+
The first fix was incomplete on 4.3.6 and 3.2.12: when another
31+
library's fork hook (such as connection_pool's, loaded before Dalli) ran
32+
first in the child, the parent's TLS session could still be ended, and
33+
4.3.6's write buffer kept a reference to the caller's value string with
34+
the meta protocol. Both are fixed in 4.3.7 and 3.2.13.
35+
36+
### Workarounds
37+
38+
Call `close` on Dalli clients before forking, outside any quiet block.
39+
patched_versions:
40+
- "~> 3.2.13"
41+
- "~> 4.3.7"
42+
- "~> 5.0.9"
43+
- "~> 5.1.3"
44+
- ">= 5.2.1"
45+
related:
46+
url:
47+
- https://github.com/petergoldstein/dalli/security/advisories/GHSA-w39f-xq2m-4g8x
48+
- https://github.com/petergoldstein/dalli/commit/62d5ad1
49+
- https://rubygems.org/gems/dalli/versions/4.3.7
50+
- https://github.com/petergoldstein/dalli/releases/tag/v4.3.7
51+
- https://rubygems.org/gems/dalli/versions/3.2.13
52+
- https://github.com/petergoldstein/dalli/releases/tag/v3.2.13
53+
- https://rubygems.org/gems/dalli/versions/5.2.1
54+
- https://github.com/petergoldstein/dalli/releases/tag/v5.2.1
55+
- https://rubygems.org/gems/dalli/versions/5.1.3
56+
- https://github.com/petergoldstein/dalli/releases/tag/v5.1.3
57+
- https://rubygems.org/gems/dalli/versions/5.0.9
58+
- https://github.com/petergoldstein/dalli/releases/tag/v5.0.9
59+
- https://rubygems.org/gems/dalli/versions/4.3.6
60+
- https://github.com/petergoldstein/dalli/releases/tag/v4.3.6
61+
- https://rubygems.org/gems/dalli/versions/3.2.12
62+
- https://github.com/petergoldstein/dalli/releases/tag/v3.2.12
63+
notes: |
64+
- No CVE in GHSA.
65+
- "A CVE has been requested through GitHub but not yet
66+
assigned, so the entry has no cve: field."
67+
- No CVSS score in GHSA; GitHub severity is medium.
68+
---
Lines changed: 78 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,78 @@
1+
---
2+
layout: advisory
3+
title: 'GHSA-wr87-m4jw-29x5 (dalli): Per-request raw and the JSON serializer don''t
4+
prevent unsafe deserialization'
5+
comments: false
6+
categories:
7+
- dalli
8+
advisory:
9+
gem: dalli
10+
ghsa: wr87-m4jw-29x5
11+
url: https://github.com/petergoldstein/dalli/security/advisories/GHSA-wr87-m4jw-29x5
12+
title: Per-request raw and the JSON serializer don't prevent unsafe deserialization
13+
date: 2026-10-05
14+
description: |-
15+
1. Per-request `raw: true` was ignored by some read methods, which still
16+
ran the configured serializer's `load` (Marshal by default) on values
17+
whose flags say they're serialized: in 5.1 and 5.2, `get_multi`,
18+
`get_multi_cas`, `get_multi_with_metadata`, `get_cas` and
19+
`get_with_metadata`; in 5.0, `get_with_metadata`; in 4.x, `get`,
20+
`gat` and `fetch` with the binary protocol, and `get_with_metadata`;
21+
in 3.x, `get`, `gat` and `fetch`.
22+
2. `serializer: JSON` resolves to `JSON.load`. With the json gem before
23+
3.0, `JSON.load` honors `json_class` when the json additions are
24+
loaded, so a crafted value can instantiate classes that define
25+
`json_create`.
26+
27+
Exploiting either requires write access to the memcached instance and
28+
an application relying on per-request `raw: true` or `serializer: JSON`
29+
to avoid unsafe deserialization. Patched versions add
30+
`Dalli::JSONSerializer`, which reads with `JSON.parse`.
31+
32+
The first fix (5.2.1, 5.1.3, 5.0.9, 4.3.6 and 3.2.12) was incomplete:
33+
on 5.0, 4.3 and 3.2, `cas` and `cas!` (and `fetch_with_lock` on 5.0,
34+
and on 4.3 with the meta protocol) still deserialized values read with
35+
`raw: true`, and on every line but 3.2 a raw read still honored flags a
36+
reply carried unasked. Both are fixed in 5.2.2, 5.1.4, 5.0.10, 4.3.7
37+
and 3.2.13.
38+
39+
### Workarounds
40+
41+
Use a serializer that only parses data, such as one wrapping
42+
`JSON.parse`, instead of `serializer: JSON`.
43+
patched_versions:
44+
- "~> 3.2.13"
45+
- "~> 4.3.7"
46+
- "~> 5.0.10"
47+
- "~> 5.1.4"
48+
- ">= 5.2.2"
49+
related:
50+
url:
51+
- https://github.com/petergoldstein/dalli/security/advisories/GHSA-wr87-m4jw-29x5
52+
- https://github.com/petergoldstein/dalli/commit/8529428
53+
- https://rubygems.org/gems/dalli/versions/5.2.2
54+
- https://github.com/petergoldstein/dalli/releases/tag/v5.2.2
55+
- https://rubygems.org/gems/dalli/versions/5.1.4
56+
- https://github.com/petergoldstein/dalli/releases/tag/v5.1.4
57+
- https://rubygems.org/gems/dalli/versions/5.0.10
58+
- https://github.com/petergoldstein/dalli/releases/tag/v5.0.10
59+
- https://rubygems.org/gems/dalli/versions/4.3.7
60+
- https://github.com/petergoldstein/dalli/releases/tag/v4.3.7
61+
- https://rubygems.org/gems/dalli/versions/3.2.13
62+
- https://github.com/petergoldstein/dalli/releases/tag/v3.2.13
63+
- https://rubygems.org/gems/dalli/versions/5.2.1
64+
- https://github.com/petergoldstein/dalli/releases/tag/v5.2.1
65+
- https://rubygems.org/gems/dalli/versions/5.1.3
66+
- https://github.com/petergoldstein/dalli/releases/tag/v5.1.3
67+
- https://rubygems.org/gems/dalli/versions/5.0.9
68+
- https://github.com/petergoldstein/dalli/releases/tag/v5.0.9
69+
- https://rubygems.org/gems/dalli/versions/4.3.6
70+
- https://github.com/petergoldstein/dalli/releases/tag/v4.3.6
71+
- https://rubygems.org/gems/dalli/versions/3.2.12
72+
- https://github.com/petergoldstein/dalli/releases/tag/v3.2.12
73+
notes: |
74+
- No CVE in GHSA.
75+
- "A CVE has been requested through GitHub but not yet
76+
assigned, so the entry has no cve: field."
77+
- No CVSS score in GHSA; GitHub severity is low.
78+
---

0 commit comments

Comments
 (0)