PT-2026-65657 · Rubygems · Sqlite3+1

Published

2026-07-28

·

Updated

2026-07-28

CVSS v4.0

2.0

Low

VectorAV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Summary

Using Database#create aggregate, #create aggregate handler, or Database#define aggregator to define an aggregate function, and then using an open statement calling that function after the database has been explicitly closed will result in an invalid memory read and a segmentation fault.

Mitigation

Upgrade to sqlite3 gem v2.9.5 or later.
As a workaround, avoid using an aggregate function after closing the database.

Severity

The sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-J7FR-3V8C-3QC3

Affected Products

Sqlite3
Sqlite3-Ruby