Description
There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.
Problem types
CWE-197: Numeric Truncation Error
Product status
Any version before 3.50.2
Credits
Vlad Stolyarov of Google's Threat Analysis Group, with assistance from Google Big Sleep
References
seclists.org/fulldisclosure/2025/Sep/57
seclists.org/fulldisclosure/2025/Sep/56
seclists.org/fulldisclosure/2025/Sep/53
seclists.org/fulldisclosure/2025/Sep/58
seclists.org/fulldisclosure/2025/Sep/49
www.openwall.com/lists/oss-security/2025/09/06/1
cert-portal.siemens.com/productcert/html/ssa-485750.html
cert-portal.siemens.com/productcert/html/ssa-225816.html
www.sqlite.org/...280ecdd833007c9d8dd595edb295b984c2b487b5c8