diff --git a/gems/dalli/GHSA-6wmv-xq9m-fmp7.yml b/gems/dalli/GHSA-6wmv-xq9m-fmp7.yml new file mode 100644 index 0000000000..da23fd300c --- /dev/null +++ b/gems/dalli/GHSA-6wmv-xq9m-fmp7.yml @@ -0,0 +1,57 @@ +--- +gem: dalli +ghsa: 6wmv-xq9m-fmp7 +url: https://github.com/petergoldstein/dalli/security/advisories/GHSA-6wmv-xq9m-fmp7 +title: Memcached command injection through numeric arguments to incr/decr + and fetch_with_lock +date: 2026-09-24 +description: | + Dalli's meta protocol request formatter wrote some numeric arguments + into memcached commands without converting them to integers. If an + application passes an attacker-controlled String to one of these + arguments, CRLF sequences in it are sent to memcached as additional + commands on the same connection, letting the attacker run arbitrary + memcached commands, such as overwriting keys or running `flush_all`. + + The affected arguments are the `default` (initial value) argument of + `Dalli::Client#incr` and `#decr`, and the `lock_ttl` and + `recache_threshold` arguments of `Dalli::Client#fetch_with_lock` + (4.2.0 and later). + + In 3.2.x and 4.x, only clients created with `protocol: :meta` are + affected; the default binary protocol is not. All 5.x configurations + are affected. + + An application is only exploitable if untrusted input reaches one of + these arguments. + + ### Workarounds + + Convert values to integers before passing them, e.g. + `Integer(params[:initial], 10)`. On 3.2.x and 4.x, use the default + binary protocol instead of `protocol: :meta`. +cvss_v3: 7.7 +unaffected_versions: + - "< 3.2.0" +patched_versions: + - "~> 3.2.9" + - "~> 4.3.4" + - "~> 5.0.7" + - ">= 5.1.1" +related: + url: + - https://github.com/petergoldstein/dalli/security/advisories/GHSA-6wmv-xq9m-fmp7 + - https://github.com/petergoldstein/dalli/commit/7bd7daf + - https://rubygems.org/gems/dalli/versions/5.1.1 + - https://github.com/petergoldstein/dalli/releases/tag/v5.1.1 + - https://rubygems.org/gems/dalli/versions/5.0.7 + - https://github.com/petergoldstein/dalli/releases/tag/v5.0.7 + - https://rubygems.org/gems/dalli/versions/4.3.4 + - https://github.com/petergoldstein/dalli/releases/tag/v4.3.4 + - https://rubygems.org/gems/dalli/versions/3.2.9 + - https://github.com/petergoldstein/dalli/releases/tag/v3.2.9 +notes: | + - No CVE in GHSA. + - "A CVE has been requested through GitHub but not yet + assigned, so the entry has no cve: field." + - cvss_v3 from GHSA URL.