GHSA-mwm8-39rw-8826: Use After Free

Published Oct 2, 2026
·
Updated

Summary

Using Database#createaggregate, #createaggregatehandler, or Database#defineaggregator to define an aggregate function that takes two or more arguments, and then evaluating it over TEXT or BLOB column values, can free the Ruby objects holding those arguments while a later argument is still being converted, during ordinary garbage collection. The aggregate's step method then receives an incorrect object, or the process crashes with a segmentation fault.

Mitigation

Upgrade to sqlite3 gem v2.9.6 or later.

There is no reliable workaround. If you cannot upgrade, avoid defining aggregate functions that take two or more arguments. Restricting column value sizes is not a mitigation: smaller values make the defect fire less often but do not prevent it.

Severity

The sqlite3-ruby maintainers assess this as Medium severity (CVSS 4.0 score 6.3). It is reached through ordinary garbage collection without any unusual code structuring: an application is exposed whenever it evaluates a multi-argument aggregate over TEXT or BLOB values whose size an attacker can influence. The demonstrated impact is an incorrect value passed to the aggregate's step method, or a process crash; no controlled memory write or general denial-of-service exploit has been demonstrated.

Credits

Reported by Jeremy Daer (@jeremy).

Affected Software

1 affected componentFixes available
rubygems/sqlite3>=1.4.0<=2.9.5
2.9.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade rubygems/sqlite3 to a version that resolves this vulnerability.

    Fixed in 2.9.6
  2. Upgrade

    Upgrade sqlite3 gem to a version that resolves this vulnerability.

    Fixed in v2.9.6
  3. Compensating control

    If you cannot upgrade, avoid defining aggregate functions that take two or more arguments, particularly when evaluating them over attacker-influenced TEXT or BLOB values.

Event History

Oct 2, 2026
Advisory Published
via GitHub·11:11 PM
Data Sourced
via GitHub·11:11 PM
DescriptionWeaknessAffected Software

Frequently Asked Questions

1

Which applications are exposed to this issue?

An application is exposed when it defines an aggregate function with two or more arguments using Database#create_aggregate, #create_aggregate_handler, or #define_aggregator, and evaluates it over TEXT or BLOB column values whose size an attacker can influence.

2

What conditions are needed to trigger the defect?

The aggregate must have at least two arguments and process TEXT or BLOB values. Ordinary Ruby garbage collection can trigger the issue while a later argument is being converted; no unusual code structure is required.

3

What can happen if the vulnerability is triggered?

The aggregate step method can receive an incorrect object, or the process can crash with a segmentation fault.

4

What should be done if an immediate upgrade is not possible?

There is no reliable workaround. Avoid defining aggregate functions that take two or more arguments until the sqlite3 gem can be upgraded to version 2.9.6 or later; limiting column value sizes does not prevent the issue.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203