PT-2026-65657 · Rubygems · Sqlite3+1

Publicado

2026-07-28

·

Atualizado

2026-07-28

CVSS v4.0

2.0

Baixa

VetorAV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Summary

Using Database#create aggregate, #create aggregate handler, or Database#define aggregator to define an aggregate function, and then using an open statement calling that function after the database has been explicitly closed will result in an invalid memory read and a segmentation fault.

Mitigation

Upgrade to sqlite3 gem v2.9.5 or later.
As a workaround, avoid using an aggregate function after closing the database.

Severity

The sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack.

Exploit

Correção

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

GHSA-J7FR-3V8C-3QC3

Produtos afetados

Sqlite3
Sqlite3-Ruby