Skip to content

Unbounded decompression and reply sizes allow memory exhaustion

Moderate
petergoldstein published GHSA-3553-vcg5-72jw Oct 5, 2026

Package

bundler dalli (rubygems)

Affected versions

< 3.2.12
>= 4.0.0, < 4.3.6
>= 5.0.0, < 5.0.9
>= 5.1.0, < 5.1.3
>= 5.2.0, < 5.2.1

Patched versions

3.2.12
4.3.6
5.0.9
5.1.3
5.2.1

Description

Summary

  1. Values flagged as compressed were inflated with no size limit. A ~130 KB stored item expands to 128 MB on read (about 1000:1), regardless of the client's compress or serializer settings.
  2. The size in a reply (a meta VA <size>, or a binary body length) was used to read or buffer that many bytes, so a hostile or compromised server could make the client allocate gigabytes.

Preconditions

Write access to the memcached instance (a shared or exposed instance, another tenant), or a malicious server or proxy.

Affected versions

All versions.

Fix

A new decompressed_max_bytes option (default 128 MiB; nil disables it) caps decompression: the built-in compressors inflate incrementally and raise Dalli::UnmarshalError once the output passes it. Custom compressors whose decompress takes only the data keep working, without the cap. Reply sizes over 1 GiB (memcached's largest item) or negative raise Dalli::DalliError before any read. Fixed in 5.2.1, 5.1.3, 5.0.9, 4.3.6 and 3.2.12.

Severity

Moderate

CVE ID

No known CVE

Weaknesses

Improper Handling of Highly Compressed Data (Data Amplification)

The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output. Learn more on MITRE.

Memory Allocation with Excessive Size Value

The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated. Learn more on MITRE.