Buffer overflow in SQLite - CVE-2025-6965
Published: July 22, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error when processing aggregated terms. A remote attacker can pass specially crafted input to the application where the number of aggregate terms exceeds the number of columns available, trigger memory corruption and perform a denial of service (DoS) attack.
Affected software
MySQL Server
SUSE Manager Server 4.3
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 12 SP5
SUSE Manager Retail Branch Server 4.3
SUSE Manager Proxy 4.3
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
visionOS
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
watchOS
Ubuntu
macOS
Basesystem Module
openSUSE Leap
tvOS
Apple iOS
iPadOS
openEuler
Fedora
SecurityCenter
IBM Observability with Instana
Netcool Operations Insight
Oracle Communications Converged Charging System
Red Hat Advanced Cluster Security for Kubernetes
Oracle Communications Network Analytics Data Director
Oracle Communications Cloud Native Core Network Exposure Function
Oracle Communications Cloud Native Core Certificate Management
AppDynamics NodeJS Agent
Service Interconnect
OpenShift File Integrity Operator
OpenShift Compliance Operator
Red Hat Advanced Cluster Management for Kubernetes
Cryostat
Red Hat build of Keycloak
Storage Defender – Data Protect
Guardium Data Security Center (GDSC)
IBM Security Verify Directory
Oracle Communications Network Charging and Control
IBM Edge Application Manager
Red Hat OpenShift Container Platform
Communications Unified Assurance
Oracle Communications Instant Messaging Server
IBM Qradar SIEM
MySQL Workbench
IBM CICS TX Advanced
Oracle Financial Services Compliance Studio
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
sqlite (Red Hat package)
sqlite3 (Ubuntu package)
mingw64-sqlite-static
mingw64-sqlite
mingw32-sqlite-static
mingw32-sqlite
mingw-sqlite (Red Hat package)
sqlite-doc
sqlite-libs
sqlite-devel
sqlite
lemon
sqlite-debugsource
sqlite-help
sqlite-debuginfo
sqlite-tcl
sqlite-tools
sqlite-analyzer
libsqlite3-0
libsqlite3-0-debuginfo
libsqlite3-0-debuginfo-32bit
libsqlite3-0-32bit
sqlite3-debuginfo
sqlite3
sqlite3-devel
sqlite3-debugsource
sqlite3-tcl
sqlite3-tcl-debuginfo
libsqlite3-0-32bit-debuginfo
sqlite3-doc
rhel-- (Red Hat package)
spice-client-win (Red Hat package)
firefox
PeopleSoft Enterprise PeopleTools
Oracle Communications Convergent Charging Controller
Siebel CRM Cloud Applications
Oracle Communications Cloud Native Core Policy
Oracle Communications Cloud Native Core Unified Data Repository
Red Hat OpenShift Serverless
Multicluster Engine for Kubernetes
OpenShift Virtualization
Red Hat Ceph Storage
How to mitigate CVE-2025-6965
SecurityCenter - update to SC-202508.1
visionOS - addressed in versions 2.6, 26.0 23M336
IBM Observability with Instana - update to 1.0.302
Netcool Operations Insight - update to 1.6.15
Storage Defender – Data Protect - update to 2.1.0
Guardium Data Security Center (GDSC) - update to 3.8.5
Red Hat Advanced Cluster Security for Kubernetes - update to 4.7.9
IBM Qradar SIEM - update to 7.5.0 Update Pack 13 IF01
IBM Security Verify Directory - update to 10.0.4.0.1
watchOS - addressed in versions 11.6, 26.0 23R352
macOS - addressed in versions 15.6 24G84, 26.0 25A354
tvOS - addressed in versions 18.6, 26.0 23J353
Apple iOS - addressed in versions 18.6 22G86, 26.0 23A341
iPadOS - addressed in versions 18.6 22G86, 26.0 23A341
AppDynamics NodeJS Agent - update to 25.12.1
Red Hat OpenShift Serverless - update to 1
Service Interconnect - update to 1
OpenShift File Integrity Operator - update to 1.3.7
OpenShift Compliance Operator - update to 1.8.0
Multicluster Engine for Kubernetes - addressed in versions 2.6.8, 2.7.6, 2.8.3
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.12.5, 2.13.4
sqlite (Red Hat package) - addressed in versions 3.7.17-9.el7_9.1, 3.26.0-18.el8_8.2, 3.26.0-20.el8_10, 3.34.1-7.el9_4.1, 3.34.1-8.el9_6, 3.46.1-5.el10_0
sqlite3 (Ubuntu package) - addressed in versions 3.8.2-1ubuntu2.2+esm5, 3.11.0-1ubuntu1.5+esm3, 3.22.0-1ubuntu0.7+esm2, 3.31.1-4ubuntu0.7+esm1, 3.37.2-2ubuntu0.5, 3.45.1-1ubuntu2.4, 3.46.1-3ubuntu0.2
mingw64-sqlite-static - update to 3.26.0.0-2
mingw64-sqlite - update to 3.26.0.0-2
mingw32-sqlite-static - update to 3.26.0.0-2
mingw32-sqlite - update to 3.26.0.0-2
mingw-sqlite (Red Hat package) - update to 3.26.0.0-2.el8_10
sqlite-doc - addressed in versions 3.26.0-20, 3.42.0-5
sqlite-libs - addressed in versions 3.26.0-20, 3.42.0-5
sqlite-devel - addressed in versions 3.26.0-20, 3.42.0-5
sqlite - addressed in versions 3.26.0-20, 3.42.0-5
lemon - addressed in versions 3.26.0-20, 3.42.0-5
sqlite-debugsource - addressed in versions 3.32.3-8, 3.37.2-8, 3.42.0-4
sqlite-help - addressed in versions 3.32.3-8, 3.37.2-8, 3.42.0-4
sqlite-devel - addressed in versions 3.32.3-8, 3.37.2-8, 3.42.0-4
sqlite-debuginfo - addressed in versions 3.32.3-8, 3.37.2-8, 3.42.0-4
sqlite - addressed in versions 3.32.3-8, 3.37.2-8, 3.42.0-4
sqlite-tcl - update to 3.42.0-5
sqlite-tools - update to 3.42.0-5
sqlite-analyzer - update to 3.42.0-5
sqlite - addressed in versions 3.46.1-4.fc41, 3.47.2-5.fc42
libsqlite3-0 - addressed in versions 3.50.2-9.41.1, 3.50.2-150000.3.33.1
libsqlite3-0-debuginfo - addressed in versions 3.50.2-9.41.1, 3.50.2-150000.3.33.1
libsqlite3-0-debuginfo-32bit - update to 3.50.2-9.41.1
libsqlite3-0-32bit - addressed in versions 3.50.2-9.41.1, 3.50.2-150000.3.33.1
sqlite3-debuginfo - addressed in versions 3.50.2-9.41.1, 3.50.2-150000.3.33.1
sqlite3 - addressed in versions 3.50.2-9.41.1, 3.50.2-150000.3.33.1
sqlite3-devel - addressed in versions 3.50.2-9.41.1, 3.50.2-150000.3.33.1
sqlite3-debugsource - addressed in versions 3.50.2-9.41.1, 3.50.2-150000.3.33.1
sqlite3-tcl - addressed in versions 3.50.2-9.41.1, 3.50.2-150000.3.33.1
sqlite3-tcl-debuginfo - update to 3.50.2-150000.3.33.1
libsqlite3-0-32bit-debuginfo - update to 3.50.2-150000.3.33.1
sqlite3-doc - update to 3.50.2-150000.3.33.1
Cryostat - update to 4.1.0
OpenShift Virtualization - update to 4.12.20
Red Hat OpenShift Container Platform - addressed in versions 4.12.82, 4.13.61, 4.14.55, 4.14.58, 4.15.56, 4.16.46, 4.17.37, 4.17.42, 4.18.22, 4.18.27, 4.19.7, 4.19.17, 4.20.0
rhel-- (Red Hat package) - update to 7/x86_64/21064/sqlite/3.7.17-9.el7_9.1/src/fd431d51/package">sqlite-3.7.17-9.el7_9.1
Red Hat Ceph Storage - update to 7.1
spice-client-win (Red Hat package) - addressed in versions 8.10-3.el8_2.1, 8.10-3.el8_4.1, 8.10-3.el8_6.1, 8.10-3.el8_8.1
IBM CICS TX Advanced - update to 10.1.0.0 ifix42
Red Hat build of Keycloak - update to 26.2.11
firefox - update to 140.8.0-1
External References
Related Security Bulletins
- Memory corruption in SQLite
- Red Hat Enterprise Linux 8 update for the nodejs:22 module
- Red Hat Enterprise Linux 10 update for sqlite
- Red Hat Enterprise Linux 9 update for sqlite
- Red Hat Enterprise Linux 8 update for sqlite
- Red Hat Enterprise Linux 9 update for sqlite
- Ubuntu update for sqlite3
- Red Hat Enterprise Linux 7 Extended Lifecycle Support update for sqlite
- Ubuntu update for sqlite3
- Anolis OS update for sqlite
- Red Hat Enterprise Linux 8 update for sqlite
- SUSE update for sqlite3
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.19
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- SUSE update for sqlite3
- Multiple vulnerabilities in IBM Security Verify Directory
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.6
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat Ceph Storage 7
- Multiple vulnerabilities in Red Hat Ceph Storage 7
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- Anolis OS update for sqlite
- Anolis OS update for sqlite
- Anolis OS update for sqlite
- Red Hat Enterprise Linux 8 update for mingw-sqlite
- Anolis OS update for mingw-sqlite
- Multiple vulnerabilities in IBM QRadar SIEM
- Tenable Security Center update for third-party components
- openEuler 24.03 LTS SP2 update for sqlite
- openEuler 24.03 LTS SP1 update for sqlite
- Multiple vulnerabilities in IBM CICS TX Advanced
- openEuler 24.03 LTS update for sqlite
- Multiple vulnerabilities in Apple macOS Tahoe
- Multiple vulnerabilities in Apple iOS 26 and iPadOS 26
- Multiple vulnerabilities in Apple watchOS
- Multiple vulnerabilities in Apple visionOS
- Multiple vulnerabilities in Apple tvOS
- Multiple vulnerabilities in IBM Observability with Instana
- Multiple vulnerabilities in OpenShift Virtualization 4.12
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.8
- Fedora 41 update for sqlite
- Fedora 42 update for sqlite
- Multiple vulnerabilities in IBM Edge Application Manager
- Multiple vulnerabilities in macOS Sequoia
- Multiple vulnerabilities in Apple visionOS
- Multiple vulnerabilities in Apple tvOS
- Multiple vulnerabilities in Apple iOS and iPadOS
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Unified Data Repository
- Multiple vulnerabilities in Oracle Communications Network Analytics Data Director
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Certificate Management
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Policy
- Multiple vulnerabilities in Oracle Communications Convergent Charging Controller
- Multiple vulnerabilities in Oracle Communications Network Charging and Control
- Multiple vulnerabilities in Oracle Communications Converged Charging System
- Multiple vulnerabilities in Communications Unified Assurance
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.13
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.7
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.19
- Multiple vulnerabilities in Oracle Communications Instant Messaging Server
- Multiple vulnerabilities in Oracle Financial Services Compliance Studio
- Multiple vulnerabilities in MySQL Workbench
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.20
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.18
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in OpenShift Compliance Operator
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in Red Hat build of Cryostat
- Multiple vulnerabilities in OpenShift File Integrity Operator
- Multiple vulnerabilities in Red Hat build of Keycloak 26.2
- Multiple vulnerabilities in IBM Guardium Data Security Center
- Multiple vulnerabilities in IBM Storage Defender - Data Protect
- Multiple vulnerabilities in Red Hat Advanced Cluster Security (RHACS) 4.7
- Red Hat Enterprise Linux 8 update for spice-client-win
- Red Hat Enterprise Linux 8 update for spice-client-win
- Red Hat Enterprise Linux 8 update for spice-client-win
- Red Hat Enterprise Linux 8 update for spice-client-win
- Multiple vulnerabilities in Siebel CRM Cloud Applications
- Multiple vulnerabilities in PeopleSoft Enterprise PeopleTools
- Multiple vulnerabilities in MySQL Server
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Anolis OS update for firefox
- Splunk AppDynamics NodeJS Agent update for third-party components
- Multiple vulnerabilities in Service Interconnect
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Exposure Function
- openEuler 22.03 LTS SP4 update for sqlite
- openEuler 20.03 LTS SP4 update for sqlite