CVE-2025-29088

Published: April 12, 2025Last modified: November 26, 2025

Description

An issue in sqlite v.3.49.0 allows an attacker to cause a denial of service via the SQLITE_DBCONFIG_LOOKASIDE component

Severity score breakdown

ParameterValue
Base score5.5
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Notes

NB: The score seems wrong. The bug is in the C API, that a remote attacker has no access to. See e.g. https://sqlite.org/forum/forumpost/48f365daec7e50af01350d72c19c317f02e5fc0d3b1e778256d1fbd8081eec5d See also CVE-2025-52099 which is a bogus copy of this CVE.

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSsqliteNot affected (3.40.0-r0)
25 LTSsqliteNot affected (3.49.2-r0)
StreamsqliteFixed (3.49.1-r0)
Hardened Containers23 LTSsqliteNot affected (3.40.0-r0)
StreamsqliteFixed (3.49.1-r0)

References

ON THIS PAGE