GHSA-mwm8-39rw-8826Medium▾ Sunlitsqlite3-ruby: Use-After-Free in SQLite Aggregate Arguments in Heap-Allocated Argument Array
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Using Database#create_aggregate, #create_aggregate_handler, or Database#define_aggregator to define an aggregate function that takes two or more arguments, and then evaluating it over TEXT or BLOB column values, can free the Ruby objects holding those arguments while a later argument is still being converted, during ordinary garbage collection. The aggregate's step method then receives an incorrect object, or the process crashes with a segmentation fault.
Upgrade to sqlite3 gem v2.9.6 or later.
There is no reliable workaround. If you cannot upgrade, avoid defining aggregate functions that take two or more arguments. Restricting column value sizes is not a mitigation: smaller values make the defect fire less often but do not prevent it.
The sqlite3-ruby maintainers assess this as Medium severity (CVSS 4.0 score 6.3). It is reached through ordinary garbage collection without any unusual code structuring: an application is exposed whenever it evaluates a multi-argument aggregate over TEXT or BLOB values whose size an attacker can influence. The demonstrated impact is an incorrect value passed to the aggregate's step method, or a process crash; no controlled memory write or general denial-of-service exploit has been demonstrated.
Reported by Jeremy Daer (@jeremy).
sqlite3 >= 1.4.0, <= 2.9.5Upgrade to a patched release:
sqlite3 2.9.6Connected by shared product, vendor, weakness, or advisory.
CVE-2025-20802Medium· 6.7In geniezone, there is a possible memory corruption due to use after free
CVE-2025-1012High· 7.5A race during concurrent delazification could have led to a use-after-free
CVE-2025-1010High· 8.8An attacker could have caused a use-after-free via the Custom Highlight API, leading to a potentially exploitable crash
CVE-2025-1009Critical· 9.8An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable crash
CVE-2025-14372Medium· 6.1Use after free in Password Manager in Google Chrome prior to 143.0.7499.110 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
CVE-2025-14326Critical· 9.8Use-after-free in the Audio/Video: GMP component