CVE-2019-5018: Canonical Ubuntu Linux

High severity, CVSS 8.1. EPSS: 6.7% chance of exploitation in the next 30 days.

An exploitable use after free vulnerability exists in the window function functionality of Sqlite3 3.26.0. A specially crafted SQL command can cause a use after free vulnerability, potentially resulting in remote code execution. An attacker can send a malicious SQL command to trigger this vulnerability.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 16.04 only; version 18.04 only; version 19.04 only; version 19.10 only
  • Sqlite Sqlite: version 3.26.0 only

Published 2019-05-10. Last modified 2026-06-17.