CVE-2026-54620

NameCVE-2026-54620
Descriptionsqlite3 provides Ruby bindings for the SQLite3 embedded database. From 2.1.0 to 2.9.4, the callbacks used for SQLite aggregate functions can be freed while still referenced during aggregation, resulting in a use-after-free. This issue is fixed in version 2.9.5.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ruby-sqlite3 (PTS)bullseye1.4.2-3vulnerable
bookworm1.4.2-4vulnerable
trixie1.7.3-1vulnerable
forky, sid2.9.5-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ruby-sqlite3source(unstable)2.9.5-1

Notes

https://github.com/sparklemotion/sqlite3-ruby/security/advisories/GHSA-j7fr-3v8c-3qc3
https://github.com/sparklemotion/sqlite3-ruby/pull/711
Fixed by: https://github.com/sparklemotion/sqlite3-ruby/commit/b24e1e6076528b7f95f99acf7a81c70d0004c726 (v2.9.5)

Search for package or bug name: Reporting problems