Security release. Fixes GHSA-6wmv-xq9m-fmp7, a memcached command injection through numeric arguments. Upgrading is recommended.
Security:
- Fix memcached command injection through numeric arguments (GHSA-6wmv-xq9m-fmp7)
- The
defaultargument ofincr/decr, andfetch_with_lock'slock_ttlandrecache_threshold, were written into the meta protocol command without conversion, so a String containing CRLF injected additional memcached commands (e.g.set,flush_all) on the connection - These arguments must now be Integers, or Strings of decimal digits; anything else raises
ArgumentErrorbefore a request is sent - As defense in depth,
RequestFormatternow converts every numeric flag it writes (D,J,N,R,T) to an Integer - Affects 3.2.0 and later (3.2.x only with
protocol: :meta); fixed in 5.1.1 and 4.3.4 - Thanks to oss-security-shop for the report
- The
Performance:
- Reduce Ruby overhead on the single-key
getpath by about 28% (#1160)- A plain
getbuilds itsmgrequest with one string interpolation instead of going throughmeta_get's keyword arguments, and skips option handling when called without options - A
VA <size> f<flags>hit line is parsed in place instead of being split into tokens - The key check for control characters and whitespace uses a byte class that matches the same ASCII bytes as
[\p{Cntrl}\s], about 5x faster; this applies to every operation that sends a key - Allocations per
gethit drop from 23 to 16 - Thanks to Julian Richard Contreras for this contribution
- A plain
- Speed up multi-server
get_multiby about 30% (4 servers, 100 keys), and bring small batches in line with 2.7.11 (#1161)- Each server's queries and terminating noop are sent before the next server's are built, so memcached answers earlier servers while later ones are prepared
- A server's queries are built in one pass with
RequestFormatter.multi_meta_get, and plainget_multino longer requests the CAS value it discards (get_multi_casstill does) - Pipelined replies are parsed in one pass over the returned flags
- Routing many keys checks each server's
alive?once per call instead of twice per key, and the ring's binary search runs over plain integers - Thanks to Julian Richard Contreras for this contribution
Development:
- Fix offenses reported by RuboCop 1.91 and require
rubocop >= 1.91(#1162)- RuboCop 1.91 adds
Style/DirectiveScope; single-statementdisable/enablepairs becomedisable-nextdirectives, which older RuboCop versions do not recognize - Removes a misplaced
# encoding: asciicomment inclient.rbthat Ruby had always ignored
- RuboCop 1.91 adds