GHSA-mwm8-39rw-8826

Suggest an improvement
Source
https://github.com/advisories/GHSA-mwm8-39rw-8826
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-mwm8-39rw-8826/GHSA-mwm8-39rw-8826.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-mwm8-39rw-8826
Published
2026-10-02T23:11:51Z
Modified
2026-10-02T23:30:05Z
Severity
  • 6.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
sqlite3-ruby: Use-After-Free in SQLite Aggregate Arguments in Heap-Allocated Argument Array
Details

Summary

Using Database#create_aggregate, #create_aggregate_handler, or Database#define_aggregator to define an aggregate function that takes two or more arguments, and then evaluating it over TEXT or BLOB column values, can free the Ruby objects holding those arguments while a later argument is still being converted, during ordinary garbage collection. The aggregate's step method then receives an incorrect object, or the process crashes with a segmentation fault.

Mitigation

Upgrade to sqlite3 gem v2.9.6 or later.

There is no reliable workaround. If you cannot upgrade, avoid defining aggregate functions that take two or more arguments. Restricting column value sizes is not a mitigation: smaller values make the defect fire less often but do not prevent it.

Severity

The sqlite3-ruby maintainers assess this as Medium severity (CVSS 4.0 score 6.3). It is reached through ordinary garbage collection without any unusual code structuring: an application is exposed whenever it evaluates a multi-argument aggregate over TEXT or BLOB values whose size an attacker can influence. The demonstrated impact is an incorrect value passed to the aggregate's step method, or a process crash; no controlled memory write or general denial-of-service exploit has been demonstrated.

Credits

Reported by Jeremy Daer (@jeremy).

Database specific
{
    "cwe_ids":  [
        "CWE-416"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-10-02T23:11:51Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

RubyGems / sqlite3

Package

Name
sqlite3
Purl
pkg:gem/sqlite3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.4.0
Fixed
2.9.6

Affected versions

1.*
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.5.0.rc1
1.5.0.rc2
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.6.0.rc1
1.6.0.rc2
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5.rc1
1.6.5
1.6.6
1.6.7
1.6.8
1.6.9
1.7.0
1.7.1
1.7.2
1.7.3
2.*
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0.rc1
2.1.0.rc2
2.1.0.rc3
2.1.0
2.1.1
2.2.0
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0.rc1
2.5.0
2.6.0
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2.rc2
2.9.2
2.9.3
2.9.4
2.9.5

Database specific

last_known_affected_version_range
"<= 2.9.5"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-mwm8-39rw-8826/GHSA-mwm8-39rw-8826.json"