Integer overflow in SQLite - CVE-2025-3277,CVE-2025-29087

 

Integer overflow in SQLite - CVE-2025-3277,CVE-2025-29087

Published: May 7, 2025 / Updated: June 23, 2025


Vulnerability identifier: #VU108745
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-3277,CVE-2025-29087
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to integer overflow within the concat_ws() function. A remote attacker who can control the separator argument can pass an on overly large string to the application and perform a denial of service (DoS) attack.


Affected software

SQLite
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Basesystem Module
Ubuntu
Fedora
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Session Smart Router
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
WatsonX BI Assistant
SecurityCenter
IBM API Connect
Salt
sqlite3 (Ubuntu package)
sqlite (Red Hat package)
sqlite
libsqlite3-0-32bit-debuginfo
libsqlite3-0-32bit
libsqlite3-0
libsqlite3-0-debuginfo
sqlite3-debugsource
sqlite3-tcl
sqlite3-devel
sqlite3-debuginfo
sqlite3-tcl-debuginfo
sqlite3
PowerScale OneFS
IBM App Connect Enterprise

How to mitigate CVE-2025-3277,CVE-2025-29087

Install updates from vendor's website.

SQLite - update to 3.49.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.2.0
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component - update to 5.2.1
WatsonX BI Assistant - update to 5.2.2
SecurityCenter - addressed in versions SC-202505.1, SC-202506.1, 6.6.0
IBM API Connect - update to 10.0.8.2 ifix2
Salt - update to 3007.4
sqlite3 (Ubuntu package) - addressed in versions 3.31.1-4ubuntu0.7, 3.37.2-2ubuntu0.4, 3.45.1-1ubuntu2.3, 3.46.1-1ubuntu0.2, 3.46.1-3ubuntu0.1
sqlite (Red Hat package) - update to 3.46.1-4.el10_0
sqlite - update to 3.46.1-4.fc41
libsqlite3-0-32bit-debuginfo - update to 3.49.1-150000.3.27.1
libsqlite3-0-32bit - update to 3.49.1-150000.3.27.1
libsqlite3-0 - update to 3.49.1-150000.3.27.1
libsqlite3-0-debuginfo - update to 3.49.1-150000.3.27.1
sqlite3-debugsource - update to 3.49.1-150000.3.27.1
sqlite3-tcl - update to 3.49.1-150000.3.27.1
sqlite3-devel - update to 3.49.1-150000.3.27.1
sqlite3-debuginfo - update to 3.49.1-150000.3.27.1
sqlite3-tcl-debuginfo - update to 3.49.1-150000.3.27.1
sqlite3 - update to 3.49.1-150000.3.27.1
Session Smart Router - addressed in versions 6.2.10, 6.3.7
PowerScale OneFS - addressed in versions 9.10.1.3, 9.11.0.1
IBM App Connect Enterprise - addressed in versions 12.0.13, 12.13.0

External References

Related Security Bulletins