CVE-2026-54620

sqlite3 provides Ruby bindings for the SQLite3 embedded database. From 2.1.0 to 2.9.4, the callbacks used for SQLite aggregate functions can be freed while still referenced during aggregation, resulting in a use-after-free. This issue is fixed in version 2.9.5.
CVSS

No CVSS.

Configurations

No configuration.

History

28 Jul 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-28 17:16

Updated : 2026-07-28 18:17


NVD link : CVE-2026-54620

Mitre link : CVE-2026-54620

CVE.ORG link : CVE-2026-54620


JSON object : View

Products Affected

No product.

CWE
CWE-416

Use After Free