CVE-2025-6965

There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
GoogleCNA
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 23%
VendorProductVersion
sqlitesqlite
𝑥
< 3.50.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
sqlite3
bullseye
postponed
bookworm
no-dsa
bullseye (security)
vulnerable
forky
3.46.1-7
fixed
sid
3.46.1-7
fixed
trixie
3.46.1-7
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
sqlite3
plucky
Fixed 3.46.1-3ubuntu0.2
released
noble
Fixed 3.45.1-1ubuntu2.4
released
jammy
Fixed 3.37.2-2ubuntu0.5
released
focal
Fixed 3.31.1-4ubuntu0.7+esm1
released
bionic
Fixed 3.22.0-1ubuntu0.7+esm2
released
xenial
Fixed 3.11.0-1ubuntu1.5+esm3
released
trusty
Fixed 3.8.2-1ubuntu2.2+esm5
released
sqlite
plucky
dne
noble
dne
jammy
needs-triage
focal
needs-triage
bionic
needs-triage
xenial
needs-triage
trusty
needs-triage