CVE-2025-6965

Published: July 16, 2025Last modified: December 23, 2025

Description

There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.

Severity score breakdown

ParameterValue
Base score7.7
Attack VectorNETWORK
Attack complexityHIGH
Privileges requiredLOW
User interactionNONE
ScopeCHANGED
ConfidentialityLOW
Integrity impactHIGH
Availability impactLOW
VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L

Notes

the fixing commit doesn't apply. The version gap is too big

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSsqliteFixed (3.40.1-r4)
25 LTSsqliteFixed (3.49.2-r1)
StreamsqliteFixed (3.50.2-r0)
Hardened Containers23 LTSsqliteFixed (3.40.1-r4)
25 LTSsqliteFixed (3.49.2-r1)
StreamsqliteFixed (3.50.2-r0)

References

ON THIS PAGE