Integer overflow in SQLite - CVE-2025-3277,CVE-2025-29087
Published: May 7, 2025 / Updated: June 23, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to integer overflow within the concat_ws() function. A remote attacker who can control the separator argument can pass an on overly large string to the application and perform a denial of service (DoS) attack.
Affected software
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Basesystem Module
Ubuntu
Fedora
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Session Smart Router
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
WatsonX BI Assistant
SecurityCenter
IBM API Connect
Salt
sqlite3 (Ubuntu package)
sqlite (Red Hat package)
sqlite
libsqlite3-0-32bit-debuginfo
libsqlite3-0-32bit
libsqlite3-0
libsqlite3-0-debuginfo
sqlite3-debugsource
sqlite3-tcl
sqlite3-devel
sqlite3-debuginfo
sqlite3-tcl-debuginfo
sqlite3
PowerScale OneFS
IBM App Connect Enterprise
How to mitigate CVE-2025-3277,CVE-2025-29087
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.2.0
watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component - update to 5.2.1
WatsonX BI Assistant - update to 5.2.2
SecurityCenter - addressed in versions SC-202505.1, SC-202506.1, 6.6.0
IBM API Connect - update to 10.0.8.2 ifix2
Salt - update to 3007.4
sqlite3 (Ubuntu package) - addressed in versions 3.31.1-4ubuntu0.7, 3.37.2-2ubuntu0.4, 3.45.1-1ubuntu2.3, 3.46.1-1ubuntu0.2, 3.46.1-3ubuntu0.1
sqlite (Red Hat package) - update to 3.46.1-4.el10_0
sqlite - update to 3.46.1-4.fc41
libsqlite3-0-32bit-debuginfo - update to 3.49.1-150000.3.27.1
libsqlite3-0-32bit - update to 3.49.1-150000.3.27.1
libsqlite3-0 - update to 3.49.1-150000.3.27.1
libsqlite3-0-debuginfo - update to 3.49.1-150000.3.27.1
sqlite3-debugsource - update to 3.49.1-150000.3.27.1
sqlite3-tcl - update to 3.49.1-150000.3.27.1
sqlite3-devel - update to 3.49.1-150000.3.27.1
sqlite3-debuginfo - update to 3.49.1-150000.3.27.1
sqlite3-tcl-debuginfo - update to 3.49.1-150000.3.27.1
sqlite3 - update to 3.49.1-150000.3.27.1
Session Smart Router - addressed in versions 6.2.10, 6.3.7
PowerScale OneFS - addressed in versions 9.10.1.3, 9.11.0.1
IBM App Connect Enterprise - addressed in versions 12.0.13, 12.13.0
External References
Related Security Bulletins
- Multiple vulnerabilities in SQLite
- Tenable Security Center update for third-party components
- Red Hat Enterprise Linux 8 update for the nodejs:22 module
- Red Hat Enterprise Linux 9 update for the nodejs:22 module
- Red Hat Enterprise Linux 10 update for sqlite
- Ubuntu update for sqlite3
- SUSE update for sqlite3
- Multiple vulnerabilities in IBM API Connect
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge
- Multiple vulnerabilities in SaltStack Salt
- Tenable Security Center update for third-party components
- Multiple vulnerabilities in IBM App Connect Enterprise Certified Container
- Dell PowerScale OneFS update for third-party components
- Multiple vulnerabilities in IBM watsonx Orchestrate with watsonx Assistant Cartridge - UAB Component
- Fedora 41 update for sqlite
- Multiple vulnerabilities in IBM WatsonX BI Assistant for CP4D
- Juniper Session Smart Router update for third-party components