DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

GHSA-MWM8-39RW-8826: GHSA-MWM8-39RW-8826: Use-After-Free Vulnerability in Ruby sqlite3 Gem native extension

GHSA-MWM8-39RW-8826: Use-After-Free Vulnerability in Ruby sqlite3 Gem native extension

Vulnerability ID: GHSA-MWM8-39RW-8826
CVSS Score: 8.1
Published: 2026-10-02

A Use-After-Free (UAF) vulnerability exists in the sqlite3-ruby native C extension when marshaling arguments for user-defined SQLite aggregate functions with multiple arguments. Due to temporary heap-allocated argument arrays not being registered with the Ruby Garbage Collector, active objects can be prematurely reclaimed, resulting in memory corruption or process-level crashes.

TL;DR

A Use-After-Free flaw in the sqlite3-ruby native extension allows arbitrary memory corruption or application crash (SIGSEGV) when executing custom SQLite aggregates with multiple arguments under high memory allocation rates.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-416
  • Attack Vector: Local / Remote (depending on application exposure)
  • CVSS Score: 8.1
  • Exploit Status: PoC available in test suite
  • Impact: Memory Corruption / Denial of Service / Code Execution
  • Affected Function: rb_sqlite3_aggregator_step
  • Remediation: Upgrade to sqlite3 >= 2.9.6

Affected Systems

  • Applications using sqlite3-ruby native gem extensions running custom multi-argument aggregate functions.
  • sqlite3 (Ruby gem): < 2.9.6 (Fixed in: 2.9.6)

Code Analysis

Commit: cc5ac0c

Replace xcalloc heap allocation with ALLOCV_N to safely root Ruby VALUE elements in rb_sqlite3_aggregator_step

Mitigation Strategies

  • Upgrade the sqlite3 gem dependency to version 2.9.6 or later.
  • Avoid registering multi-argument custom SQLite aggregate functions in vulnerable environments.
  • Refactor multi-argument aggregate steps to single-argument operations by passing a concatenated or serialized string.

Remediation Steps:

  1. Audit the project's Gemfile.lock to locate references to the 'sqlite3' gem.
  2. Update the 'sqlite3' entry in the Gemfile to: gem 'sqlite3', '>= 2.9.6'
  3. Run 'bundle update sqlite3' to apply the update.
  4. Verify the resolved version in Gemfile.lock matches 2.9.6 or higher.

References


Read the full report for GHSA-MWM8-39RW-8826 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)