Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-54620

Gravedad CVSS v4.0:
BAJA
Tipo:
CWE-416 Utilización después de liberación
Fecha de publicación:
28/07/2026
Última modificación:
30/07/2026

Descripción

*** Pendiente de traducción *** sqlite3 provides Ruby bindings for the SQLite3 embedded database. From 2.1.0 to 2.9.4, the callbacks used for SQLite aggregate functions can be freed while still referenced during aggregation, resulting in a use-after-free. This issue is fixed in version 2.9.5.