From 944366ac6eeb1e29f04c600e6ce33ee7b24e03cf Mon Sep 17 00:00:00 2001 From: petergoldstein Date: Thu, 24 Sep 2026 19:10:11 -0400 Subject: [PATCH 1/2] Add GHSA-6wmv-xq9m-fmp7 for dalli Memcached command injection through numeric arguments to incr/decr and fetch_with_lock. Fixed in 3.2.9, 4.3.4, 5.0.7 and 5.1.1. Co-Authored-By: Claude Opus 5.5 (1M context) --- gems/dalli/GHSA-6wmv-xq9m-fmp7.yml | 44 ++++++++++++++++++++++++++++++ 1 file changed, 44 insertions(+) create mode 100644 gems/dalli/GHSA-6wmv-xq9m-fmp7.yml diff --git a/gems/dalli/GHSA-6wmv-xq9m-fmp7.yml b/gems/dalli/GHSA-6wmv-xq9m-fmp7.yml new file mode 100644 index 0000000000..b9471e19d2 --- /dev/null +++ b/gems/dalli/GHSA-6wmv-xq9m-fmp7.yml @@ -0,0 +1,44 @@ +--- +gem: dalli +ghsa: 6wmv-xq9m-fmp7 +url: https://github.com/petergoldstein/dalli/security/advisories/GHSA-6wmv-xq9m-fmp7 +title: Memcached command injection through numeric arguments to incr/decr + and fetch_with_lock +date: 2026-09-24 +description: | + Dalli's meta protocol request formatter wrote some numeric arguments + into memcached commands without converting them to integers. If an + application passes an attacker-controlled String to one of these + arguments, CRLF sequences in it are sent to memcached as additional + commands on the same connection, letting the attacker run arbitrary + memcached commands, such as overwriting keys or running `flush_all`. + + The affected arguments are the `default` (initial value) argument of + `Dalli::Client#incr` and `#decr`, and the `lock_ttl` and + `recache_threshold` arguments of `Dalli::Client#fetch_with_lock` + (4.2.0 and later). + + In 3.2.x and 4.x, only clients created with `protocol: :meta` are + affected; the default binary protocol is not. All 5.x configurations + are affected. + + An application is only exploitable if untrusted input reaches one of + these arguments. + + ### Workarounds + + Convert values to integers before passing them, e.g. + `Integer(params[:initial], 10)`. On 3.2.x and 4.x, use the default + binary protocol instead of `protocol: :meta`. +cvss_v3: 7.7 +unaffected_versions: + - "< 3.2.0" +patched_versions: + - "~> 3.2.9" + - "~> 4.3.4" + - "~> 5.0.7" + - ">= 5.1.1" +related: + url: + - https://github.com/petergoldstein/dalli/security/advisories/GHSA-6wmv-xq9m-fmp7 + - https://github.com/petergoldstein/dalli/commit/7bd7daf From 1958a3e178ac80d6aa4d5212d751e11482022baf Mon Sep 17 00:00:00 2001 From: petergoldstein Date: Thu, 24 Sep 2026 20:36:52 -0400 Subject: [PATCH 2/2] Add release links and notes to dalli GHSA-6wmv-xq9m-fmp7 Co-Authored-By: Claude Opus 5.5 (1M context) --- gems/dalli/GHSA-6wmv-xq9m-fmp7.yml | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/gems/dalli/GHSA-6wmv-xq9m-fmp7.yml b/gems/dalli/GHSA-6wmv-xq9m-fmp7.yml index b9471e19d2..da23fd300c 100644 --- a/gems/dalli/GHSA-6wmv-xq9m-fmp7.yml +++ b/gems/dalli/GHSA-6wmv-xq9m-fmp7.yml @@ -42,3 +42,16 @@ related: url: - https://github.com/petergoldstein/dalli/security/advisories/GHSA-6wmv-xq9m-fmp7 - https://github.com/petergoldstein/dalli/commit/7bd7daf + - https://rubygems.org/gems/dalli/versions/5.1.1 + - https://github.com/petergoldstein/dalli/releases/tag/v5.1.1 + - https://rubygems.org/gems/dalli/versions/5.0.7 + - https://github.com/petergoldstein/dalli/releases/tag/v5.0.7 + - https://rubygems.org/gems/dalli/versions/4.3.4 + - https://github.com/petergoldstein/dalli/releases/tag/v4.3.4 + - https://rubygems.org/gems/dalli/versions/3.2.9 + - https://github.com/petergoldstein/dalli/releases/tag/v3.2.9 +notes: | + - No CVE in GHSA. + - "A CVE has been requested through GitHub but not yet + assigned, so the entry has no cve: field." + - cvss_v3 from GHSA URL.