Skip to content

Fix invalid UTF-8 handling in vendored SQLite parser - #50

Open
tszymczyszyn-shopify wants to merge 1 commit into
v0.9.30-shopify-patchesfrom
tszymczyszyn/fix-sqlite3-parser-utf8
Open

tszymczyszyn-shopify wants to merge 1 commit into
v0.9.30-shopify-patchesfrom
tszymczyszyn/fix-sqlite3-parser-utf8

Conversation

@tszymczyszyn-shopify

Copy link
Copy Markdown

Summary

  • port the upstream sqlite3-parser invalid UTF-8 fix from gwenn/lemon-rs@14f422a
  • replace the unchecked byte-to-string conversion with String::from_utf8_lossy
  • bump the vendored libsql-sqlite3-parser package from 0.13.0 to 0.13.1
  • add regression coverage for invalid UTF-8 input

Why

libsql-sqlite3-parser 0.13.0 is affected by GHSA-8m95-fffc-h4c5 / CVE-2025-47736. The parser accepts byte slices, but from_bytes constructed a str without validating that those bytes were UTF-8.

The original parser project fixed this in May 2025, but libsql's vendored copy still contains the vulnerable implementation. Versioning the patched vendored package as 0.13.1 also places it outside the advisory's affected range (<=0.13.0) for downstream lockfiles.

The related upstream libsql report is tursodatabase/libsql#2052.

Test plan

  • cargo +1.98.1 fmt --all -- --check
  • cargo +1.98.1 test -p libsql-sqlite3-parser --locked
  • cargo +1.98.1 check -p libsql-sqlite3-parser --all-targets --all-features --locked
  • git diff --check

Port gwenn/lemon-rs@14f422a to replace the unchecked UTF-8 conversion with a lossy conversion. Bump the vendored parser to 0.13.1 and add regression coverage for invalid input.\n\nAddresses CVE-2025-47736 / GHSA-8m95-fffc-h4c5.
@tszymczyszyn-shopify
tszymczyszyn-shopify requested a review from a team October 6, 2026 16:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants