Rapid7

vulnerability

Oracle Linux: CVE-2020-35525: ELSA-2022-7108: sqlite security update (MODERATE)

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
Feb 20, 2020
Added
Oct 26, 2022
Modified
Dec 3, 2025

Description

In SQlite 3.31.1, a potential null pointer derreference was found in the INTERSEC query processing.
A NULL pointer dereference flaw was found in select.c of SQLite. An out-of-memory error occurs while an early out on the INTERSECT query is processing. This flaw allows an attacker to execute a potential NULL pointer dereference.

Solutions

oracle-linux-upgrade-lemonoracle-linux-upgrade-sqliteoracle-linux-upgrade-sqlite-develoracle-linux-upgrade-sqlite-docoracle-linux-upgrade-sqlite-libs
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.