Vulnerability GHSA-j7fr-3v8c-3qc3

Low Risk
LOW RISK
CVSS Score: 3.0
Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
2 months ago
July 28, 2026 at 04:23 PM UTC
sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks
2.1.0 - 2.9.4
2.1.0 - 2.9.4

Summary

sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks

Details

Summary

Using Database#create_aggregate, #create_aggregate_handler, or Database#define_aggregator to define an aggregate function, and then using an open statement calling that function after the database has been explicitly closed will result in an invalid memory read and a segmentation fault.

Mitigation

Upgrade to sqlite3 gem v2.9.5 or later.

As a workaround, avoid using an aggregate function after closing the database.

Severity

The sqlite3-ruby maintainers assess this as Low severity. It is reliably triggered after GC when code is structured in a particular way. There is no known general exploit that could be used as a denial of service attack.

Impacted packages

Timeline

Published
2 months ago
July 28, 2026 at 04:23 PM UTC
Fixed (2.9.5)
3 months ago
June 07, 2026 at 05:33 PM UTC
Last Modified
2 months ago
July 28, 2026 at 04:35 PM UTC