A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.
CVSS Details
- CVSS 3.1 Base Score: 4.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade sqlite | Mar 21, 2024 | Jan 16, 2024 |
| Debian | — | Upgrade sqlite3 | Jul 27, 2026 | Jul 27, 2026 |
| Freebsd | — | Upgrade linux-c7-sqliteUpgrade sqlite3Upgrade linux-rl9-sqlite | Oct 1, 2024 | Sep 29, 2024 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 16, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub