PT-2026-48218 · Sqlite+3 · Sqlite+3
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
SQLite versions prior to 3.53.2
Description
A heap-based buffer overflow exists in the FTS5 full-text search extension. An attacker can cause a crash or execute arbitrary code by providing a crafted database containing malicious continuation page metadata with a
szLeaf value smaller than 4. This triggers an integer underflow in the fts5ChunkIterate() function, resulting in an inflated remaining byte count during FTS5 MATCH query processing. This issue affects applications compiled with SQLITE ENABLE FTS5.Recommendations
Update to version 3.53.2 or later.
Exploit
Fix
DoS
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Rocky Linux
Sqlite
Ubuntu