{"id":"EEF-CVE-2026-97853","summary":"Unbounded allocation in decimal Decimal.round/3 driven by the places argument enables DoS","details":"## Summary\n\nMemory Allocation with Excessive Size Value vulnerability in ericmj decimal allows Denial of Service.\n\n`Decimal.round/3` builds the full result for the requested number of decimal places before the context precision (34 digits by default) is applied, so its cost grows with the `places` argument instead of with the size of the result. For positive `places` it appends `places` zero digits to the coefficient as a charlist before converting it to an integer, and for negative `places` it builds a charlist of `-places` zero digits. A single call such as `Decimal.round(Decimal.new(\"1.5\"), -50_000_000)` allocates about 5.5 GB of memory, which can exhaust available memory and get the BEAM VM killed. The oldest releases instead loop once per decimal place, consuming CPU in proportion to `places`.\n\nAny application that passes a user-supplied number of decimal places or scale to `Decimal.round/2` or `Decimal.round/3` without bounding it is exposed. The input limits added for CVE-2026-32686 do not cover the `places` argument.\n\nThis issue affects decimal: from 0.1.0 before 3.1.2.\n\n## Details\n\n`Decimal.round/3` sets the target exponent to `-places` and `do_round/5` materializes the coefficient at that exponent; `context/2` only applies the precision afterwards.\n\n- Positive `places` (introduced in 1.3.0 by commit 7a83d27): `digits ++ Enum.map(1..(exp - target_exp), fn _ -\u003e ?0 end)` followed by `:erlang.list_to_integer/1` (`lib/decimal.ex:2409` in 3.1.1). The list is built before `list_to_integer/1` raises `SystemLimitError` for results over about 1.26 million digits, the BEAM integer size limit.\n- Negative `places` (since 1.4.0): `:lists.duplicate(target_exp - exp, ?0) ++ digits` (`lib/decimal.ex:2385-2386` in 3.1.1).\n- Releases from 0.1.0 before 1.1.0: `do_round` (and in 1.0.1 `split_coef`) recurses once per decimal place for negative `places`; 1.0.1 also multiplies a power of ten by 10 on every iteration. Established by reading the code; these releases do not compile on current Elixir.\n\nMeasured on OTP 29 with 3.1.1, one call per fresh VM:\n\n| Call | Time | Peak VM memory |\n|---|---|---|\n| `Decimal.round(Decimal.new(\"1.5\"), -10_000_000)` | 0.25 s | 0.8 GB |\n| `Decimal.round(Decimal.new(\"1.5\"), -50_000_000)` | 1.2 s | 5.5 GB |\n| `Decimal.round(Decimal.new(\"1.5\"), 50_000_000)` | 2.1 s, then `SystemLimitError` | 2.4 GB |\n\nIn an `elixir:1.20.4` container started with `--memory=2g`, either of the last two calls got the VM killed (exit status 137). Over HTTP (Plug and Bandit) a 34-byte JSON body carrying `places: -50_000_000` returned after 1.25 s with server memory at 4.3 GB.\n\n## Proof of concept\n\n```elixir\nMix.install([{:decimal, \"3.1.1\"}])\n\n# Allocates about 5.5 GB.\nDecimal.round(Decimal.new(\"1.5\"), -50_000_000)\n\n# Builds a 50 million element list, then raises SystemLimitError.\nDecimal.round(Decimal.new(\"1.5\"), 50_000_000)\n```\n\n## Impact\n\nAn attacker who controls the number of decimal places an application rounds to makes one `Decimal.round/2,3` call allocate memory in proportion to that number. A value of 50 million needs about 5.5 GB, enough to get the BEAM VM killed on hosts with less memory and take down every request it serves.\n\n## Workarounds\n\nBound `places` before calling `Decimal.round/2,3`, for example to `-34..34` or to the scales the application supports.","aliases":["CVE-2026-97853","GHSA-6c27-994x-c52f"],"modified":"2026-10-10T19:56:02.464793251Z","published":"2026-10-10T19:43:45.217Z","database_specific":{"capec_ids":["CAPEC-130"],"cpe_ids":["cpe:2.3:a:ericmj:decimal:*:*:*:*:*:*:*:*"],"cwe_ids":["CWE-789"]},"references":[{"type":"ADVISORY","url":"https://github.com/ericmj/decimal/security/advisories/GHSA-6c27-994x-c52f"},{"type":"WEB","url":"https://cna.erlef.org/cves/CVE-2026-97853.html"},{"type":"WEB","url":"https://github.com/ericmj/decimal/commit/05bb73eb40ddef24eda782d905766f56a3660522"},{"type":"FIX","url":"https://github.com/ericmj/decimal/commit/338f42c8cf6a9749ab70c5af04734c6050ca3dc6"},{"type":"FIX","url":"https://github.com/ericmj/decimal/commit/3c90af4c3c2dfa4bb4c138760a326dd0eb91822b"},{"type":"PACKAGE","url":"https://hex.pm/packages/decimal"}],"affected":[{"package":{"name":"decimal","ecosystem":"Hex","purl":"pkg:hex/decimal"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.1.0"},{"fixed":"3.1.2"}]}],"versions":["0.1.1","0.1.2","0.2.0","0.2.1","0.2.2","0.2.3","0.2.4","0.2.5","1.0.0","1.0.1","1.1.0","1.1.1","1.1.2","1.2.0","1.3.0","1.3.1","1.4.0","1.4.1","1.5.0","1.6.0","1.7.0","1.8.0","1.8.1","1.9.0","1.9.0-rc.0","2.0.0","2.0.0-rc.0","2.1.0","2.1.1","2.2.0","2.3.0","2.4.0","2.4.1","3.0.0","3.1.0","3.1.1"],"database_specific":{"source":"https://cna.erlef.org/osv/EEF-CVE-2026-97853.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/ericmj/decimal","events":[{"introduced":"05bb73eb40ddef24eda782d905766f56a3660522"},{"fixed":"338f42c8cf6a9749ab70c5af04734c6050ca3dc6"},{"fixed":"3c90af4c3c2dfa4bb4c138760a326dd0eb91822b"}]}],"versions":["v3.1.1","v3.1.0","v2.4.0","v3.0.0","v2.3.0","v2.2.0","v2.1.1","v2.1.0","v2.0.0","v1.9.0-rc.0","v2.0.0-rc.0","v1.8.1","v1.8.0","v1.7.0","v1.6.0","v1.5.0","v1.4.1","v1.4.0","v1.3.1","v1.3.0","v1.2.0","v1.1.2","v1.1.1","v1.1.0","v1.0.1","v1.0.0","v0.2.5","v0.2.4","v0.2.3","v0.2.2","v0.2.1","v0.2.0","v0.1.2","v0.1.1","v0.1.0"],"database_specific":{"source":"https://cna.erlef.org/osv/EEF-CVE-2026-97853.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}],"credits":[{"name":"Peter Ullrich","type":"FINDER"},{"name":"Eric Meadows-Jönsson","type":"REMEDIATION_DEVELOPER"},{"name":"Eric Meadows-Jönsson","type":"COORDINATOR"}]}