GHSA-mwm8-39rw-8826: Use After Free
Summary
Using Database#createaggregate, #createaggregatehandler, or Database#defineaggregator to define an aggregate function that takes two or more arguments, and then evaluating it over TEXT or BLOB column values, can free the Ruby objects holding those arguments while a later argument is still being converted, during ordinary garbage collection. The aggregate's step method then receives an incorrect object, or the process crashes with a segmentation fault.
Mitigation
Upgrade to sqlite3 gem v2.9.6 or later.
There is no reliable workaround. If you cannot upgrade, avoid defining aggregate functions that take two or more arguments. Restricting column value sizes is not a mitigation: smaller values make the defect fire less often but do not prevent it.
Severity
The sqlite3-ruby maintainers assess this as Medium severity (CVSS 4.0 score 6.3). It is reached through ordinary garbage collection without any unusual code structuring: an application is exposed whenever it evaluates a multi-argument aggregate over TEXT or BLOB values whose size an attacker can influence. The demonstrated impact is an incorrect value passed to the aggregate's step method, or a process crash; no controlled memory write or general denial-of-service exploit has been demonstrated.
Credits
Reported by Jeremy Daer (@jeremy).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
rubygems/sqlite3to a version that resolves this vulnerability.Fixed in 2.9.6 - Upgrade
Upgrade
sqlite3 gemto a version that resolves this vulnerability.Fixed in v2.9.6 - Compensating control
If you cannot upgrade, avoid defining aggregate functions that take two or more arguments, particularly when evaluating them over attacker-influenced TEXT or BLOB values.
Event History
Frequently Asked Questions
Which applications are exposed to this issue?
An application is exposed when it defines an aggregate function with two or more arguments using Database#create_aggregate, #create_aggregate_handler, or #define_aggregator, and evaluates it over TEXT or BLOB column values whose size an attacker can influence.
What conditions are needed to trigger the defect?
The aggregate must have at least two arguments and process TEXT or BLOB values. Ordinary Ruby garbage collection can trigger the issue while a later argument is being converted; no unusual code structure is required.
What can happen if the vulnerability is triggered?
The aggregate step method can receive an incorrect object, or the process can crash with a segmentation fault.
What should be done if an immediate upgrade is not possible?
There is no reliable workaround. Avoid defining aggregate functions that take two or more arguments until the sqlite3 gem can be upgraded to version 2.9.6 or later; limiting column value sizes does not prevent the issue.