Summary
- Values flagged as compressed were inflated with no size limit. A ~130 KB stored item expands to 128 MB on read (about 1000:1), regardless of the client's
compress or serializer settings.
- The size in a reply (a meta
VA <size>, or a binary body length) was used to read or buffer that many bytes, so a hostile or compromised server could make the client allocate gigabytes.
Preconditions
Write access to the memcached instance (a shared or exposed instance, another tenant), or a malicious server or proxy.
Affected versions
All versions.
Fix
A new decompressed_max_bytes option (default 128 MiB; nil disables it) caps decompression: the built-in compressors inflate incrementally and raise Dalli::UnmarshalError once the output passes it. Custom compressors whose decompress takes only the data keep working, without the cap. Reply sizes over 1 GiB (memcached's largest item) or negative raise Dalli::DalliError before any read. Fixed in 5.2.1, 5.1.3, 5.0.9, 4.3.6 and 3.2.12.
Summary
compressorserializersettings.VA <size>, or a binary body length) was used to read or buffer that many bytes, so a hostile or compromised server could make the client allocate gigabytes.Preconditions
Write access to the memcached instance (a shared or exposed instance, another tenant), or a malicious server or proxy.
Affected versions
All versions.
Fix
A new
decompressed_max_bytesoption (default 128 MiB;nildisables it) caps decompression: the built-in compressors inflate incrementally and raiseDalli::UnmarshalErroronce the output passes it. Custom compressors whosedecompresstakes only the data keep working, without the cap. Reply sizes over 1 GiB (memcached's largest item) or negative raiseDalli::DalliErrorbefore any read. Fixed in 5.2.1, 5.1.3, 5.0.9, 4.3.6 and 3.2.12.