Skip to content

Six new dalli advisories - #1257

Merged
simi merged 2 commits into
rubysec:masterfrom
petergoldstein:dalli-2026-10-security
Oct 6, 2026
Merged

simi merged 2 commits into
rubysec:masterfrom
petergoldstein:dalli-2026-10-security

Conversation

@petergoldstein

@petergoldstein petergoldstein commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Adds six dalli advisories, submitted by the dalli maintainer. Five were fixed in one coordinated release (5.2.1, 5.1.3, 5.0.9, 4.3.6 and 3.2.12); a follow-up release (5.2.2, 5.1.4, 5.0.10, 4.3.7 and 3.2.13) fixed a sixth and completed two of the earlier fixes.

Advisory GitHub severity Summary
GHSA-p6pm-ch9v-44vx high Pipelined get_multi can return another key's value after an error reply
GHSA-4qp6-2jcr-596v medium Routing tokens can inject meta protocol flags, and failed requests can retry forever
GHSA-3553-vcg5-72jw medium Unbounded decompression and reply sizes allow memory exhaustion
GHSA-wr87-m4jw-29x5 low Per-request raw and the JSON serializer don't prevent unsafe deserialization
GHSA-w39f-xq2m-4g8x medium Forking can resend buffered memcached requests and desynchronize the parent's connection
GHSA-m252-9cgf-vx2w high With a namespace, a retried request reads or writes a different key

Versions

  • Each advisory affects every supported release line, from version ranges that differ per advisory (described in each entry), so none has unaffected_versions.
  • Patched: ~> 3.2.12, ~> 4.3.6, ~> 5.0.9, ~> 5.1.3 and >= 5.2.1 for most; GHSA-wr87-m4jw-29x5 is patched in ~> 3.2.13, ~> 4.3.7, ~> 5.0.10, ~> 5.1.4 and >= 5.2.2, GHSA-w39f-xq2m-4g8x in ~> 3.2.13 and ~> 4.3.7 on those lines, and GHSA-m252-9cgf-vx2w (unaffected before 4.1.0) in ~> 4.3.7, ~> 5.0.10, ~> 5.1.4 and >= 5.2.2.

Notes

  • CVEs have been requested through GitHub but not yet assigned, so the entries have no cve: field. I'll follow up once they're assigned (along with the CVE for GHSA-6wmv-xq9m-fmp7 from One new dalli advisory (GHSA-6wmv-xq9m-fmp7) #1247).
  • The GitHub advisories have a severity but no CVSS score, so the entries have no cvss_v3.
  • bundle exec rspec spec/advisories_spec.rb spec/schema_validation_spec.rb passes locally.

🤖 Generated with Claude Code

@jasnow jasnow left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • Copied the PR locally/compare 1 advisory vs my template/done/LGTM
  • Scan all 5 release URLs for reference to GHSA/done.

@jasnow
jasnow requested a review from simi October 5, 2026 23:47
….2.2/5.1.4/5.0.10/4.3.7/3.2.13

GHSA-wr87-m4jw-29x5 and GHSA-w39f-xq2m-4g8x: the first fixes were
incomplete; new patched versions and a note on what was missed.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@petergoldstein petergoldstein changed the title Five new dalli advisories Six new dalli advisories Oct 6, 2026

@jasnow jasnow left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copied the PR locally/compare 1 advisory vs my template/done/LGTM
Review new (6th) advisory/LGTM plus changes/GLTM.

@simi
simi merged commit 960b055 into rubysec:master Oct 6, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants