MEDIUM
Out Of Bounds write in FTS5 Extension in SQLite
Published Sep 8, 2025
6.9
MEDIUMCVSS 4.0
EPSS 0.35%
Description
An integer overflow exists in the FTS5 https://sqlite.org/fts5.html extension. It occurs when the size of an array of tombstone pointers is calculated and truncated into a 32-bit integer. A pointer to partially controlled data can then be written out of bounds.
Affected products
-
Affected
- 3.49.1 < 3.50
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Google
Published Sep 8, 2025
Updated Nov 18, 2025
Reserved Jul 16, 2025
Link CVE-2025-7709
CISA Vulnrichment
Updated Sep 8, 2025
Red Hat
No data
GitHub
No data