{"id":"CVE-2026-54620","summary":"sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks","details":"sqlite3 provides Ruby bindings for the SQLite3 embedded database. From 2.1.0 to 2.9.4, the callbacks used for SQLite aggregate functions can be freed while still referenced during aggregation, resulting in a use-after-free. This issue is fixed in version 2.9.5.","aliases":["GHSA-j7fr-3v8c-3qc3"],"modified":"2026-07-30T08:13:35.055095Z","published":"2026-07-28T16:23:38.389Z","database_specific":{"cwe_ids":["CWE-416"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54620.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://github.com/sparklemotion/sqlite3-ruby/releases/tag/v2.9.5"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54620.json"},{"type":"ADVISORY","url":"https://github.com/sparklemotion/sqlite3-ruby/security/advisories/GHSA-j7fr-3v8c-3qc3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54620"},{"type":"FIX","url":"https://github.com/sparklemotion/sqlite3-ruby/commit/b24e1e6076528b7f95f99acf7a81c70d0004c726"},{"type":"FIX","url":"https://github.com/sparklemotion/sqlite3-ruby/pull/711"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/sparklemotion/sqlite3-ruby","events":[{"introduced":"9a18cb9697d5bf6bdfd19e20e49934b0ce83a12a"},{"fixed":"b24e1e6076528b7f95f99acf7a81c70d0004c726"},{"fixed":"747e7de5166a0329a517402144408dfe45977962"}],"database_specific":{"extracted_events":[{"introduced":"2.1.0"},{"fixed":"2.9.5"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v2.9.4","v2.9.3","v2.9.2","v2.9.2.rc2","v2.9.2.rc1","v2.9.1","v2.9.0","v2.8.1","v2.8.0","v2.7.4","v2.7.3","v2.7.2","v2.7.1","v2.7.0","v2.6.0","v2.5.0","v2.5.0.rc1","v2.4.1","v2.4.0","v2.3.1","v2.3.0","v2.2.0","v2.1.1","v2.1.0"],"database_specific":{"vanir_signatures":[{"signature_type":"Function","signature_version":"v1","source":"https://github.com/sparklemotion/sqlite3-ruby/commit/b24e1e6076528b7f95f99acf7a81c70d0004c726","target":{"file":"ext/sqlite3/database.c","function":"sqlite3_rb_discard"},"deprecated":false,"digest":{"length":191,"function_hash":"230264218131979185470418694721117338542"},"id":"CVE-2026-54620-36ea4fd9"},{"deprecated":false,"digest":{"line_hashes":["265689249784512259660747625313946247212","131755143084933356590064351947908408322","172163203058175261443017676469810333826","99368928534202922022608717387938448892","189913336094798000787304534379186812386","214805861890130422514572409193550623479","217544246339400958419911529239314275950","99368928534202922022608717387938448892"],"threshold":0.9},"id":"CVE-2026-54620-6d62c435","signature_type":"Line","signature_version":"v1","source":"https://github.com/sparklemotion/sqlite3-ruby/commit/b24e1e6076528b7f95f99acf7a81c70d0004c726","target":{"file":"ext/sqlite3/database.c"}},{"signature_version":"v1","source":"https://github.com/sparklemotion/sqlite3-ruby/commit/b24e1e6076528b7f95f99acf7a81c70d0004c726","target":{"file":"ext/sqlite3/database.c","function":"sqlite3_rb_close"},"deprecated":false,"digest":{"function_hash":"230264218131979185470418694721117338542","length":191},"id":"CVE-2026-54620-cf0a461b","signature_type":"Function"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54620.json","vanir_signatures_modified":"2026-07-30T08:13:35Z"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"}]}