Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-54620

Опубликовано: 28 июл. 2026
Источник: redhat
CVSS3: 4.5
EPSS Низкий

Описание

A flaw was found in sqlite3-ruby, a Ruby binding for the SQLite3 embedded database. This vulnerability occurs because callbacks used for SQLite aggregate functions can be prematurely freed while still being referenced during aggregation. A local attacker could potentially exploit this use-after-free condition to cause unpredictable application behavior, which may lead to information disclosure or a denial of service (DoS).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Satellite 6rubygem-sqlite3Under investigation
Red Hat Satellite 6satellite:el8/rubygem-sqlite3Under investigation

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2508116sqlite3-ruby: sqlite3: sqlite3-ruby: Use-After-Free vulnerability in SQLite aggregate function callbacks

EPSS

Процентиль: 1%
0.00107
Низкий

4.5 Medium

CVSS3

Связанные уязвимости

ubuntu
7 дней назад

(sqlite3 provides Ruby bindings for the SQLite3 embedded database. From ...)

nvd
7 дней назад

sqlite3 provides Ruby bindings for the SQLite3 embedded database. From 2.1.0 to 2.9.4, the callbacks used for SQLite aggregate functions can be freed while still referenced during aggregation, resulting in a use-after-free. This issue is fixed in version 2.9.5.

debian
7 дней назад

sqlite3 provides Ruby bindings for the SQLite3 embedded database. From ...

github
7 дней назад

sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks

EPSS

Процентиль: 1%
0.00107
Низкий

4.5 Medium

CVSS3