PT-2026-48217 · Sqlite+3 · Sqlite+3

·

CVE-2026-11822

·

Published

2026-06-09

·

Updated

2026-09-02

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions SQLite versions prior to 3.53.2
Description Memory corruption issues exist in the FTS5 full-text search extension. An attacker can cause process crashes, memory exhaustion, or arbitrary code execution by providing a crafted database containing malformed FTS5 page data. This is exploitable when an FTS5 MATCH query is executed against the malicious database. Technical details include an out-of-bounds read in the fts5LeafSeek() function via an attacker-controlled loop bound, and a heap buffer overflow write in the fts5ChunkIterate() function caused by an integer underflow through a crafted continuation page.
Recommendations Update to version 3.53.2 or later.

Exploit

Fix

RCE

DoS

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:55603
ALSA-2026:58927
ALSA-2026:58936
ALSA-2026:58938
ALSA-2026:61242
AZL-89706
BIT-SQLITE-2026-11822
CVE-2026-11822
ECHO-ACFD-CCAB-2F14
OESA-2026-2755
OPENSUSE-SU-2026:11059-1
OPENSUSE-SU-2026:21090-1
RHSA-2026:45779
RHSA-2026:54371
RHSA-2026:54530
RHSA-2026:55601
RHSA-2026:55603
RHSA-2026:58927
RHSA-2026:58936
RHSA-2026:58938
RHSA-2026:58939
RHSA-2026:59020
RHSA-2026:59024
RHSA-2026:59956
RHSA-2026:61242
RHSA-2026:61697
RHSA-2026:62232
RHSA-2026:62236
SUSE-SU-2026:22104-1
SUSE-SU-2026:22134-1
SUSE-SU-2026:22166-1
SUSE-SU-2026:22218-1
SUSE-SU-2026:2527-1
SUSE-SU-2026:2528-1
USN-8480-1

Affected Products

Linuxmint
Rocky Linux
Sqlite
Ubuntu