SB2026042953 - SUSE update for sqlite3
Published: April 29, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Use of uninitialized resource (CVE-ID: CVE-2025-70873)
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to use of uninitialized resource in zipfileInflate() in the zipfile extension when processing a crafted ZIP file through the zipfile() functionality. A remote attacker can supply a crafted ZIP file with a forged uncompressed size to disclose sensitive information.
Only instances where the zipfile extension is enabled and used to process untrusted ZIP content are vulnerable.
2) Integer overflow (CVE-ID: CVE-2025-7709)
The vulnerability allows a remote user to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow in the FTS5 extension. A remote user can pass specially crafted data to the application, trigger an integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Remediation
Install update from vendor's website.