Skip to content

chore(deps): update dependency sqlite3 to v2.9.6 [security] - #763

Merged
mensfeld merged 1 commit into
masterfrom
renovate/rubygems-sqlite3-vulnerability
Oct 5, 2026
Merged

mensfeld merged 1 commit into
masterfrom
renovate/rubygems-sqlite3-vulnerability

Conversation

@coipond-renovate

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
sqlite3 '2.9.5' → '2.9.6' age confidence

sqlite3-ruby: Use-After-Free in SQLite Aggregate Arguments in Heap-Allocated Argument Array

GHSA-mwm8-39rw-8826

More information

Details

Summary

Using Database#create_aggregate, #create_aggregate_handler, or Database#define_aggregator to define an aggregate function that takes two or more arguments, and then evaluating it over TEXT or BLOB column values, can free the Ruby objects holding those arguments while a later argument is still being converted, during ordinary garbage collection. The aggregate's step method then receives an incorrect object, or the process crashes with a segmentation fault.

Mitigation

Upgrade to sqlite3 gem v2.9.6 or later.

There is no reliable workaround. If you cannot upgrade, avoid defining aggregate functions that take two or more arguments. Restricting column value sizes is not a mitigation: smaller values make the defect fire less often but do not prevent it.

Severity

The sqlite3-ruby maintainers assess this as Medium severity (CVSS 4.0 score 6.3). It is reached through ordinary garbage collection without any unusual code structuring: an application is exposed whenever it evaluates a multi-argument aggregate over TEXT or BLOB values whose size an attacker can influence. The demonstrated impact is an incorrect value passed to the aggregate's step method, or a process crash; no controlled memory write or general denial-of-service exploit has been demonstrated.

Credits

Reported by Jeremy Daer (@​jeremy).

Severity

  • CVSS Score: 6.3 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@coipond-renovate coipond-renovate Bot added the dependencies Pull requests that update dependency files label Oct 5, 2026
@mensfeld
mensfeld merged commit 91ec83f into master Oct 5, 2026
13 checks passed
@mensfeld
mensfeld deleted the renovate/rubygems-sqlite3-vulnerability branch October 5, 2026 06:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update dependency files

Development

Successfully merging this pull request may close these issues.

1 participant