PT-2026-56525 · Sqlite+2 · Sqlite+2

·

CVE-2026-50812

·

Published

2026-07-08

·

Updated

2026-08-30

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions SQLite version 3.53.1 SQLite trunk builds prior to check-in e807d4e3798efd53
Description A NULL pointer dereference in the SQLite Session Extension allows an attacker to cause a denial of service by supplying a malformed changeset blob. This occurs when the sqlite3changeset apply v3() function applies a corrupt changeset and calls sqlite3 value type() using a NULL sqlite3 value pointer.
Recommendations Update SQLite version 3.53.1 to a version containing the fix. Update SQLite trunk builds to check-in e807d4e3798efd53 or later.

Exploit

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-50812
ECHO-F08C-2B40-760B
MGASA-2026-0305
OESA-2026-3492
OESA-2026-3493
OESA-2026-3494
OESA-2026-3495
RHSA-2026:39023
USN-8565-1

Affected Products

Linuxmint
Sqlite
Ubuntu