CVE-2026-54620
Gravedad CVSS v4.0:
BAJA
Tipo:
CWE-416
Utilización después de liberación
Fecha de publicación:
28/07/2026
Última modificación:
30/07/2026
Descripción
*** Pendiente de traducción *** sqlite3 provides Ruby bindings for the SQLite3 embedded database. From 2.1.0 to 2.9.4, the callbacks used for SQLite aggregate functions can be freed while still referenced during aggregation, resulting in a use-after-free. This issue is fixed in version 2.9.5.
Impacto
Puntuación base 4.0
2.00
Gravedad 4.0
BAJA
Referencias a soluciones, herramientas e información
- https://github.com/sparklemotion/sqlite3-ruby/commit/b24e1e6076528b7f95f99acf7a81c70d0004c726
- https://github.com/sparklemotion/sqlite3-ruby/pull/711
- https://github.com/sparklemotion/sqlite3-ruby/releases/tag/v2.9.5
- https://github.com/sparklemotion/sqlite3-ruby/security/advisories/GHSA-j7fr-3v8c-3qc3



