Back

HIGH

Integer Truncation on SQLite

Published Jul 15, 2025

Description

There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.

Affected products

Remediation

Red Hat statement

This vulnerability in SQLite is categorized as Important rather than Critical because, although it involves memory corruption, the conditions required to trigger it are relatively constrained. The flaw arises when a query causes the number of aggregate terms to exceed internal limits, leading to potential buffer overflows or memory mismanagement. However, exploitation requires the ability to craft complex SQL queries and interact with the SQLite engine in a specific manner—typically through direct SQL input. There is no known evidence of arbitrary code execution, privilege escalation, or remote exploitability as a direct result of this flaw. Additionally, most SQLite deployments are embedded in applications where input is tightly controlled or sanitized.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Weaknesses (1)

References (18)

Change history (6)
  1. CISA ADP
    • SSVC technical impact

      changed from total to partial

    • SSVC exploitation

      changed from poc to none

  2. CISA ADP
    • SSVC technical impact

      changed from partial to total

    • SSVC exploitation

      changed from none to poc

  3. CISA ADP
    • SSVC technical impact

      changed from total to partial

    • SSVC exploitation

      changed from poc to none

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Google
Published Jul 15, 2025
Updated Apr 29, 2026
Reserved Jul 1, 2025
CISA Vulnrichment
Updated Jul 15, 2025
NVD
Status Analyzed
Modified Jun 26, 2026
Red Hat
Severity Important
Public date Jul 15, 2025
ENISA EUVD
Assigner Google
Published Jul 15, 2025
Updated Apr 29, 2026
Exploited since n/a
EUVD-2025-21441 GHSA-2M69-GCR7-JV3Q