CVE-2026-54620
LOWsqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
Title source: cnaDescription
sqlite3 provides Ruby bindings for the SQLite3 embedded database. From 2.1.0 to 2.9.4, the callbacks used for SQLite aggregate functions can be freed while still referenced during aggregation, resulting in a use-after-free. This issue is fixed in version 2.9.5.
References (4)
Core 4
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/sparklemotion/sqlite3-ruby/security/advisories/GHSA-j7fr-3v8c-3qc3
X_Refsource_Misc x_refsource_misc
https://github.com/sparklemotion/sqlite3-ruby/pull/711
X_Refsource_Misc x_refsource_misc
https://github.com/sparklemotion/sqlite3-ruby/commit/b24e1e6076528b7f95f99acf7a81c70d0004c726
X_Refsource_Misc x_refsource_misc
https://github.com/sparklemotion/sqlite3-ruby/releases/tag/v2.9.5
Scores
CVSS v4
2.0
EPSS
0.0011
EPSS Percentile
1.3%
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-416
Status
published
Products (3)
rubygems/sqlite3
2.1.0 - 2.9.5RubyGems
rubygems/sqlite3-ruby
2.1.0 - 2.9.5RubyGems
sparklemotion/sqlite3-ruby
>= 2.1.0, < 2.9.5
Published
Jul 28, 2026
Tracked Since
Jul 28, 2026