CVE-2025-7709
Published: September 9, 2025Last modified: December 23, 2025
Description
An integer overflow exists in the FTS5 https://sqlite.org/fts5.html extension. It occurs when the size of an array of tombstone pointers is calculated and truncated into a 32-bit integer. A pointer to partially controlled data can then be written out of bounds.
Notes
23-lts is not affected as the bug was in a later version.
Status
| Product | Release | Package | Status |
|---|---|---|---|
| Alpaquita Linux | 25 LTS | sqlite | Fixed (3.50.3-r0) |
| Stream | sqlite | Fixed (3.50.3-r0) | |
| Hardened Containers | 25 LTS | sqlite | Fixed (3.50.3-r0) |
| Stream | sqlite | Fixed (3.50.3-r0) |