PT-2026-56525 · Sqlite+2 · Sqlite+2
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
SQLite version 3.53.1
SQLite trunk builds prior to check-in e807d4e3798efd53
Description
A NULL pointer dereference in the SQLite Session Extension allows an attacker to cause a denial of service by supplying a malformed changeset blob. This occurs when the
sqlite3changeset apply v3() function applies a corrupt changeset and calls sqlite3 value type() using a NULL sqlite3 value pointer.Recommendations
Update SQLite version 3.53.1 to a version containing the fix.
Update SQLite trunk builds to check-in e807d4e3798efd53 or later.
Exploit
Fix
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Sqlite
Ubuntu