PT-2026-48218 · Sqlite+3 · Sqlite+3

·

CVE-2026-11824

·

Published

2026-06-09

·

Updated

2026-09-02

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SQLite versions prior to 3.53.2
Description A heap-based buffer overflow exists in the FTS5 full-text search extension. An attacker can cause a crash or execute arbitrary code by providing a crafted database containing malicious continuation page metadata with a szLeaf value smaller than 4. This triggers an integer underflow in the fts5ChunkIterate() function, resulting in an inflated remaining byte count during FTS5 MATCH query processing. This issue affects applications compiled with SQLITE ENABLE FTS5.
Recommendations Update to version 3.53.2 or later.

Exploit

Fix

DoS

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:55603
ALSA-2026:58927
ALSA-2026:58936
ALSA-2026:58938
AZL-89703
BIT-SQLITE-2026-11824
CVE-2026-11824
ECHO-3BE4-5309-FE51
OESA-2026-2755
OPENSUSE-SU-2026:11059-1
OPENSUSE-SU-2026:21090-1
RHSA-2026:45779
SUSE-SU-2026:22104-1
SUSE-SU-2026:22134-1
SUSE-SU-2026:22166-1
SUSE-SU-2026:22218-1
SUSE-SU-2026:2527-1
SUSE-SU-2026:2528-1
USN-8480-1

Affected Products

Linuxmint
Rocky Linux
Sqlite
Ubuntu