PT-2026-109865 · Decimal · Decimal
CVSS v4.0
6.9
Medium
| Vector | AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
decimal versions 0.1.0 through 3.1.1
Description
A memory allocation issue exists in the
Decimal.round/3 function that allows for a Denial of Service. The function builds the full result for the requested number of decimal places before applying context precision, causing memory consumption to grow based on the places argument rather than the result size. For positive places, the software appends zero digits to the coefficient as a charlist; for negative places, it builds a charlist of zero digits. A large value, such as -50,000,000, can allocate approximately 5.5 GB of memory, potentially exhausting available resources and causing the BEAM VM to be killed. In older releases, this issue manifests as high CPU consumption due to looping once per decimal place. Applications are exposed if they pass user-supplied values to Decimal.round/2 or Decimal.round/3 without proper bounding.Recommendations
Update decimal to version 3.1.2 or later.
As a temporary workaround, bound the
places argument before calling Decimal.round/2 or Decimal.round/3, for example, restricting it to a range such as -34..34 or to the specific scales supported by the application.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Decimal