CVE-2019-5018: Canonical Ubuntu Linux
High severity, CVSS 8.1. EPSS: 6.7% chance of exploitation in the next 30 days.
An exploitable use after free vulnerability exists in the window function functionality of Sqlite3 3.26.0. A specially crafted SQL command can cause a use after free vulnerability, potentially resulting in remote code execution. An attacker can send a malicious SQL command to trigger this vulnerability.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 16.04 only; version 18.04 only; version 19.04 only; version 19.10 only
- Sqlite Sqlite: version 3.26.0 only
Published 2019-05-10. Last modified 2026-06-17.