Skip to content

Commit 406813f

Browse files
jasnowRubySec CI
authored andcommitted
Updated advisory posts against rubysec/ruby-advisory-db@0e150d5
1 parent bdc21f9 commit 406813f

1 file changed

Lines changed: 64 additions & 0 deletions

File tree

Lines changed: 64 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,64 @@
1+
---
2+
layout: advisory
3+
title: 'GHSA-6wmv-xq9m-fmp7 (dalli): Memcached command injection through numeric arguments
4+
to incr/decr and fetch_with_lock'
5+
comments: false
6+
categories:
7+
- dalli
8+
advisory:
9+
gem: dalli
10+
ghsa: 6wmv-xq9m-fmp7
11+
url: https://github.com/petergoldstein/dalli/security/advisories/GHSA-6wmv-xq9m-fmp7
12+
title: Memcached command injection through numeric arguments to incr/decr and fetch_with_lock
13+
date: 2026-09-24
14+
description: |-
15+
Dalli's meta protocol request formatter wrote some numeric arguments
16+
into memcached commands without converting them to integers. If an
17+
application passes an attacker-controlled String to one of these
18+
arguments, CRLF sequences in it are sent to memcached as additional
19+
commands on the same connection, letting the attacker run arbitrary
20+
memcached commands, such as overwriting keys or running `flush_all`.
21+
22+
The affected arguments are the `default` (initial value) argument of
23+
`Dalli::Client#incr` and `#decr`, and the `lock_ttl` and
24+
`recache_threshold` arguments of `Dalli::Client#fetch_with_lock`
25+
(4.2.0 and later).
26+
27+
In 3.2.x and 4.x, only clients created with `protocol: :meta` are
28+
affected; the default binary protocol is not. All 5.x configurations
29+
are affected.
30+
31+
An application is only exploitable if untrusted input reaches one of
32+
these arguments.
33+
34+
### Workarounds
35+
36+
Convert values to integers before passing them, e.g.
37+
`Integer(params[:initial], 10)`. On 3.2.x and 4.x, use the default
38+
binary protocol instead of `protocol: :meta`.
39+
cvss_v3: 7.7
40+
unaffected_versions:
41+
- "< 3.2.0"
42+
patched_versions:
43+
- "~> 3.2.9"
44+
- "~> 4.3.4"
45+
- "~> 5.0.7"
46+
- ">= 5.1.1"
47+
related:
48+
url:
49+
- https://github.com/petergoldstein/dalli/security/advisories/GHSA-6wmv-xq9m-fmp7
50+
- https://github.com/petergoldstein/dalli/commit/7bd7daf
51+
- https://rubygems.org/gems/dalli/versions/5.1.1
52+
- https://github.com/petergoldstein/dalli/releases/tag/v5.1.1
53+
- https://rubygems.org/gems/dalli/versions/5.0.7
54+
- https://github.com/petergoldstein/dalli/releases/tag/v5.0.7
55+
- https://rubygems.org/gems/dalli/versions/4.3.4
56+
- https://github.com/petergoldstein/dalli/releases/tag/v4.3.4
57+
- https://rubygems.org/gems/dalli/versions/3.2.9
58+
- https://github.com/petergoldstein/dalli/releases/tag/v3.2.9
59+
notes: |
60+
- No CVE in GHSA.
61+
- "A CVE has been requested through GitHub but not yet
62+
assigned, so the entry has no cve: field."
63+
- cvss_v3 from GHSA URL.
64+
---

0 commit comments

Comments
 (0)