In SQLite 3.44.0 through 3.49.0 before 3.49.1, the concat_ws() SQL function can cause memory to be written beyond the end of a malloc-allocated buffer. If the separator argument is attacker-controlled and has a large string (e.g., 2MB or more), an integer overflow occurs in calculating the size of the result buffer, and thus malloc may not allocate enough memory.
CVSS Details
- CVSS 3.1 Base Score: 3.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade sqlite | Aug 8, 2025 | Apr 7, 2025 |
| Debian | — | Upgrade sqlite3 | Jul 23, 2026 | Jul 23, 2026 |
| Freebsd | — | Upgrade sqlite | May 2, 2025 | Apr 30, 2025 |
| Ibm Aix | — | Apply the fix or workaround for rpm_advisory3 | Sep 25, 2025 | Jul 17, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 7, 2025 |
| Suse | — | Upgrade sqlite3-docUpgrade libsqlite3-0-x86-64-v3Upgrade sqlite3-develUpgrade sqlite3Upgrade sqlite3-tclUpgrade libsqlite3-0-32bitUpgrade libsqlite3-0 | Dec 5, 2025 | Jun 27, 2025 |
| Ubuntu | — | Upgrade libsqlite3-0 | May 26, 2025 | Apr 7, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub