Home

Description

There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.

PUBLISHED Reserved 2025-07-01 | Published 2025-07-15 | Updated 2026-04-29 | Assigner Google




HIGH: 7.2CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/S:N/AU:N/R:U/V:D/RE:L/U:Green

Problem types

CWE-197: Numeric Truncation Error

Product status

Default status
unaffected

Any version before 3.50.2
affected

Credits

Vlad Stolyarov of Google's Threat Analysis Group, with assistance from Google Big Sleep finder

References

seclists.org/fulldisclosure/2025/Sep/57

seclists.org/fulldisclosure/2025/Sep/56

seclists.org/fulldisclosure/2025/Sep/53

seclists.org/fulldisclosure/2025/Sep/58

seclists.org/fulldisclosure/2025/Sep/49

www.openwall.com/lists/oss-security/2025/09/06/1

cert-portal.siemens.com/productcert/html/ssa-485750.html

cert-portal.siemens.com/productcert/html/ssa-225816.html

www.sqlite.org/...280ecdd833007c9d8dd595edb295b984c2b487b5c8

cve.org (CVE-2025-6965)

nvd.nist.gov (CVE-2025-6965)

Download JSON