SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database.
CVSS Details
- CVSS 4.0 Base Score: 8.5 (HIGH)
- CVSS 4.0 Vector: (CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade sqlite | Aug 19, 2026 | Jun 9, 2026 |
| Amazon_linux_2023 | — | Upgrade nodejs24-develUpgrade sqlite-develUpgrade sqlite-toolsUpgrade nodejs24Upgrade v8-12.4-develUpgrade sqlite-tclUpgrade nodejs24-libs-debuginfoUpgrade nodejs22-libsUpgrade sqlite-analyzer-debuginfoUpgrade nodejs22-develUpgrade nodejs24-libsUpgrade lemon-debuginfoUpgrade nodejs24-debuginfoUpgrade sqlite-docUpgrade lemonUpgrade nodejs24-full-i18nUpgrade nodejs22-npmUpgrade nodejs22-debugsourceUpgrade nodejs22-docsUpgrade sqlite-tools-debuginfoUpgrade nodejs24-docsUpgrade sqlite-libs-debuginfoUpgrade sqlite-libsUpgrade sqlite-tcl-debuginfoUpgrade sqlite-analyzerUpgrade nodejs24-debugsourceUpgrade nodejs22Upgrade sqlite-debuginfoUpgrade nodejs24-npmUpgrade sqlite-debugsourceUpgrade nodejs22-debuginfoUpgrade v8-13.6-develUpgrade nodejs22-libs-debuginfoUpgrade nodejs22-full-i18nUpgrade sqlite | Jul 8, 2026 | Jun 9, 2026 |
| Debian | — | Upgrade sqlite3 | Sep 21, 2026 | Jun 9, 2026 |
| Redhat Openshift | — | Upgrade rhcos | Sep 18, 2026 | Jun 9, 2026 |
| Redhat_linux | — | Upgrade v8-13.6-develUpgrade sqlite-docUpgrade mingw32-sqliteUpgrade nodejs-packaging-bundlerUpgrade lemonUpgrade nodejs-develUpgrade lemon-debuginfoUpgrade sqlite-develUpgrade nodejs-libs-debuginfoUpgrade mingw64-sqlite-staticUpgrade nodejs-debugsourceUpgrade mingw32-sqlite-staticUpgrade sqlite-analyzer-debuginfoUpgrade v8-12.4-develUpgrade sqlite-libsUpgrade nodejs-debuginfoUpgrade nodejs-nodemonUpgrade mingw64-sqlite-debuginfoUpgrade sqlite-debugsourceUpgrade sqliteUpgrade npmUpgrade mingw64-sqliteUpgrade sqlite-libs-debuginfoUpgrade sqlite-tools-debuginfoUpgrade nodejs-docsUpgrade mingw32-sqlite-debuginfoUpgrade nodejs-libsNo solution existsUpgrade nodejsUpgrade nodejs-packagingUpgrade nodejs-full-i18nUpgrade sqlite-debuginfoUpgrade sqlite-tcl-debuginfo | Aug 26, 2026 | Jun 9, 2026 |
| Rocky_linux | — | Upgrade sqlite-develUpgrade v8-13.6-develUpgrade nodejs-develUpgrade nodejs-libs-debuginfoUpgrade nodejs-debuginfoUpgrade nodejs-debugsourceUpgrade nodejsUpgrade sqlite-libsUpgrade nodejs-full-i18nUpgrade sqliteUpgrade sqlite-debuginfoUpgrade nodejs-libsUpgrade v8-12.4-develUpgrade npmUpgrade sqlite-debugsourceUpgrade sqlite-libs-debuginfoUpgrade lemon-debuginfoUpgrade lemon | Aug 27, 2026 | Aug 25, 2026 |
| Ubuntu | — | Upgrade libsqlite3-0 | Jun 30, 2026 | Jun 29, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jun 22, 2026 | Jun 9, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub