Memory Corruption Vulnerability in SQLite by SQLite Consortium
CVE-2025-6965

7.2HIGH

Key Information:

Vendor

Sqlite

Status
Vendor
CVE Published:
15 July 2025

What is CVE-2025-6965?

A vulnerability exists in SQLite versions prior to 3.50.2 that allows the number of aggregate terms in a query to surpass the available number of columns. This mismatch can result in memory corruption, potentially leading to instability or crashes within applications using these affected versions. It is highly recommended to upgrade to version 3.50.2 or later to mitigate the risks associated with this issue.

Affected Version(s)

SQLite 0 < 3.50.2

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vlad Stolyarov of Google's Threat Analysis Group, with assistance from Google Big Sleep
.
CVE-2025-6965 : Memory Corruption Vulnerability in SQLite by SQLite Consortium