Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-54620

Опубликовано: 28 июл. 2026
Источник: debian
EPSS Низкий

Описание

sqlite3 provides Ruby bindings for the SQLite3 embedded database. From 2.1.0 to 2.9.4, the callbacks used for SQLite aggregate functions can be freed while still referenced during aggregation, resulting in a use-after-free. This issue is fixed in version 2.9.5.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ruby-sqlite3fixed2.9.5-1package

Примечания

  • https://github.com/sparklemotion/sqlite3-ruby/security/advisories/GHSA-j7fr-3v8c-3qc3

  • https://github.com/sparklemotion/sqlite3-ruby/pull/711

  • Fixed by: https://github.com/sparklemotion/sqlite3-ruby/commit/b24e1e6076528b7f95f99acf7a81c70d0004c726 (v2.9.5)

EPSS

Процентиль: 1%
0.00107
Низкий

Связанные уязвимости

ubuntu
7 дней назад

(sqlite3 provides Ruby bindings for the SQLite3 embedded database. From ...)

CVSS3: 4.5
redhat
7 дней назад

A flaw was found in sqlite3-ruby, a Ruby binding for the SQLite3 embedded database. This vulnerability occurs because callbacks used for SQLite aggregate functions can be prematurely freed while still being referenced during aggregation. A local attacker could potentially exploit this use-after-free condition to cause unpredictable application behavior, which may lead to information disclosure or a denial of service (DoS).

nvd
7 дней назад

sqlite3 provides Ruby bindings for the SQLite3 embedded database. From 2.1.0 to 2.9.4, the callbacks used for SQLite aggregate functions can be freed while still referenced during aggregation, resulting in a use-after-free. This issue is fixed in version 2.9.5.

github
7 дней назад

sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks

EPSS

Процентиль: 1%
0.00107
Низкий