SB2026042954 - SUSE update for sqlite3



SB2026042954 - SUSE update for sqlite3

Published: April 29, 2026

Security Bulletin ID SB2026042954
Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Use of uninitialized resource (CVE-ID: CVE-2025-70873)

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to use of uninitialized resource in zipfileInflate() in the zipfile extension when processing a crafted ZIP file through the zipfile() functionality. A remote attacker can supply a crafted ZIP file with a forged uncompressed size to disclose sensitive information.

Only instances where the zipfile extension is enabled and used to process untrusted ZIP content are vulnerable.


2) Integer overflow (CVE-ID: CVE-2025-7709)

The vulnerability allows a remote user to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in the FTS5 extension. A remote user can pass specially crafted data to the application, trigger an integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Remediation

Install update from vendor's website.