Skip to content

Fix invalid UTF-8 handling in vendored SQLite parser - #50

Merged
tszymczyszyn-shopify merged 1 commit into
v0.9.30-shopify-patchesfrom
tszymczyszyn/fix-sqlite3-parser-utf8
Oct 7, 2026
Merged

tszymczyszyn-shopify merged 1 commit into
v0.9.30-shopify-patchesfrom
tszymczyszyn/fix-sqlite3-parser-utf8

Conversation

@tszymczyszyn-shopify

Copy link
Copy Markdown

Summary

  • port the upstream sqlite3-parser invalid UTF-8 fix from gwenn/lemon-rs@14f422a
  • replace the unchecked byte-to-string conversion with String::from_utf8_lossy
  • bump the vendored libsql-sqlite3-parser package from 0.13.0 to 0.13.1
  • add regression coverage for invalid UTF-8 input

Why

libsql-sqlite3-parser 0.13.0 is affected by GHSA-8m95-fffc-h4c5 / CVE-2025-47736. The parser accepts byte slices, but from_bytes constructed a str without validating that those bytes were UTF-8.

The original parser project fixed this in May 2025, but libsql's vendored copy still contains the vulnerable implementation. Versioning the patched vendored package as 0.13.1 also places it outside the advisory's affected range (<=0.13.0) for downstream lockfiles.

The related upstream libsql report is tursodatabase/libsql#2052.

Test plan

  • cargo +1.98.1 fmt --all -- --check
  • cargo +1.98.1 test -p libsql-sqlite3-parser --locked
  • cargo +1.98.1 check -p libsql-sqlite3-parser --all-targets --all-features --locked
  • git diff --check

Port gwenn/lemon-rs@14f422a to replace the unchecked UTF-8 conversion with a lossy conversion. Bump the vendored parser to 0.13.1 and add regression coverage for invalid input.\n\nAddresses CVE-2025-47736 / GHSA-8m95-fffc-h4c5.
@tszymczyszyn-shopify
tszymczyszyn-shopify requested a review from a team October 6, 2026 16:46
@tszymczyszyn-shopify
tszymczyszyn-shopify merged commit f06c62c into v0.9.30-shopify-patches Oct 7, 2026
18 checks passed
@tszymczyszyn-shopify
tszymczyszyn-shopify deleted the tszymczyszyn/fix-sqlite3-parser-utf8 branch October 7, 2026 07:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants