GHSA-MWM8-39RW-8826: Use-After-Free Vulnerability in Ruby sqlite3 Gem native extension
Vulnerability ID: GHSA-MWM8-39RW-8826
CVSS Score: 8.1
Published: 2026-10-02
A Use-After-Free (UAF) vulnerability exists in the sqlite3-ruby native C extension when marshaling arguments for user-defined SQLite aggregate functions with multiple arguments. Due to temporary heap-allocated argument arrays not being registered with the Ruby Garbage Collector, active objects can be prematurely reclaimed, resulting in memory corruption or process-level crashes.
TL;DR
A Use-After-Free flaw in the sqlite3-ruby native extension allows arbitrary memory corruption or application crash (SIGSEGV) when executing custom SQLite aggregates with multiple arguments under high memory allocation rates.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-416
- Attack Vector: Local / Remote (depending on application exposure)
- CVSS Score: 8.1
- Exploit Status: PoC available in test suite
- Impact: Memory Corruption / Denial of Service / Code Execution
- Affected Function: rb_sqlite3_aggregator_step
- Remediation: Upgrade to sqlite3 >= 2.9.6
Affected Systems
- Applications using sqlite3-ruby native gem extensions running custom multi-argument aggregate functions.
-
sqlite3 (Ruby gem): < 2.9.6 (Fixed in:
2.9.6)
Code Analysis
Commit: cc5ac0c
Replace xcalloc heap allocation with ALLOCV_N to safely root Ruby VALUE elements in rb_sqlite3_aggregator_step
Mitigation Strategies
- Upgrade the sqlite3 gem dependency to version 2.9.6 or later.
- Avoid registering multi-argument custom SQLite aggregate functions in vulnerable environments.
- Refactor multi-argument aggregate steps to single-argument operations by passing a concatenated or serialized string.
Remediation Steps:
- Audit the project's Gemfile.lock to locate references to the 'sqlite3' gem.
- Update the 'sqlite3' entry in the Gemfile to: gem 'sqlite3', '>= 2.9.6'
- Run 'bundle update sqlite3' to apply the update.
- Verify the resolved version in Gemfile.lock matches 2.9.6 or higher.
References
- GHSA-MWM8-39RW-8826 Advisory Entry
- GitHub Pull Request #733 Fix implementation
- Fix Commit cc5ac0c
- v2.9.6 Tag Release Details
Read the full report for GHSA-MWM8-39RW-8826 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)