Memory Corruption Vulnerability in SQLite by SQLite Consortium
CVE-2025-6965
7.2HIGH
What is CVE-2025-6965?
A vulnerability exists in SQLite versions prior to 3.50.2 that allows the number of aggregate terms in a query to surpass the available number of columns. This mismatch can result in memory corruption, potentially leading to instability or crashes within applications using these affected versions. It is highly recommended to upgrade to version 3.50.2 or later to mitigate the risks associated with this issue.
Affected Version(s)
SQLite 0 < 3.50.2
References
CVSS V4
Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Vlad Stolyarov of Google's Threat Analysis Group, with assistance from Google Big Sleep