Buffer overflow in SQLite - CVE-2025-6965

 

Buffer overflow in SQLite - CVE-2025-6965

Published: July 22, 2025


Vulnerability identifier: #VU113156
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-6965
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error when processing aggregated terms. A remote attacker can pass specially crafted input to the application where the number of aggregate terms exceeds the number of columns available, trigger memory corruption and perform a denial of service (DoS) attack.


Affected software

SQLite
MySQL Server
SUSE Manager Server 4.3
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 12 SP5
SUSE Manager Retail Branch Server 4.3
SUSE Manager Proxy 4.3
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
visionOS
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
watchOS
Ubuntu
macOS
Basesystem Module
openSUSE Leap
tvOS
Apple iOS
iPadOS
openEuler
Fedora
SecurityCenter
IBM Observability with Instana
Netcool Operations Insight
Oracle Communications Converged Charging System
Red Hat Advanced Cluster Security for Kubernetes
Oracle Communications Network Analytics Data Director
Oracle Communications Cloud Native Core Network Exposure Function
Oracle Communications Cloud Native Core Certificate Management
AppDynamics NodeJS Agent
Service Interconnect
OpenShift File Integrity Operator
OpenShift Compliance Operator
Red Hat Advanced Cluster Management for Kubernetes
Cryostat
Red Hat build of Keycloak
Storage Defender – Data Protect
Guardium Data Security Center (GDSC)
IBM Security Verify Directory
Oracle Communications Network Charging and Control
IBM Edge Application Manager
Red Hat OpenShift Container Platform
Communications Unified Assurance
Oracle Communications Instant Messaging Server
IBM Qradar SIEM
MySQL Workbench
IBM CICS TX Advanced
Oracle Financial Services Compliance Studio
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
sqlite (Red Hat package)
sqlite3 (Ubuntu package)
mingw64-sqlite-static
mingw64-sqlite
mingw32-sqlite-static
mingw32-sqlite
mingw-sqlite (Red Hat package)
sqlite-doc
sqlite-libs
sqlite-devel
sqlite
lemon
sqlite-debugsource
sqlite-help
sqlite-debuginfo
sqlite-tcl
sqlite-tools
sqlite-analyzer
libsqlite3-0
libsqlite3-0-debuginfo
libsqlite3-0-debuginfo-32bit
libsqlite3-0-32bit
sqlite3-debuginfo
sqlite3
sqlite3-devel
sqlite3-debugsource
sqlite3-tcl
sqlite3-tcl-debuginfo
libsqlite3-0-32bit-debuginfo
sqlite3-doc
rhel-- (Red Hat package)
spice-client-win (Red Hat package)
firefox
PeopleSoft Enterprise PeopleTools
Oracle Communications Convergent Charging Controller
Siebel CRM Cloud Applications
Oracle Communications Cloud Native Core Policy
Oracle Communications Cloud Native Core Unified Data Repository
Red Hat OpenShift Serverless
Multicluster Engine for Kubernetes
OpenShift Virtualization
Red Hat Ceph Storage

How to mitigate CVE-2025-6965

Install updates from vendor's website.

SQLite - update to 3.50.2
SecurityCenter - update to SC-202508.1
visionOS - addressed in versions 2.6, 26.0 23M336
IBM Observability with Instana - update to 1.0.302
Netcool Operations Insight - update to 1.6.15
Storage Defender – Data Protect - update to 2.1.0
Guardium Data Security Center (GDSC) - update to 3.8.5
Red Hat Advanced Cluster Security for Kubernetes - update to 4.7.9
IBM Qradar SIEM - update to 7.5.0 Update Pack 13 IF01
IBM Security Verify Directory - update to 10.0.4.0.1
watchOS - addressed in versions 11.6, 26.0 23R352
macOS - addressed in versions 15.6 24G84, 26.0 25A354
tvOS - addressed in versions 18.6, 26.0 23J353
Apple iOS - addressed in versions 18.6 22G86, 26.0 23A341
iPadOS - addressed in versions 18.6 22G86, 26.0 23A341
AppDynamics NodeJS Agent - update to 25.12.1
Red Hat OpenShift Serverless - update to 1
Service Interconnect - update to 1
OpenShift File Integrity Operator - update to 1.3.7
OpenShift Compliance Operator - update to 1.8.0
Multicluster Engine for Kubernetes - addressed in versions 2.6.8, 2.7.6, 2.8.3
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.12.5, 2.13.4
sqlite (Red Hat package) - addressed in versions 3.7.17-9.el7_9.1, 3.26.0-18.el8_8.2, 3.26.0-20.el8_10, 3.34.1-7.el9_4.1, 3.34.1-8.el9_6, 3.46.1-5.el10_0
sqlite3 (Ubuntu package) - addressed in versions 3.8.2-1ubuntu2.2+esm5, 3.11.0-1ubuntu1.5+esm3, 3.22.0-1ubuntu0.7+esm2, 3.31.1-4ubuntu0.7+esm1, 3.37.2-2ubuntu0.5, 3.45.1-1ubuntu2.4, 3.46.1-3ubuntu0.2
mingw64-sqlite-static - update to 3.26.0.0-2
mingw64-sqlite - update to 3.26.0.0-2
mingw32-sqlite-static - update to 3.26.0.0-2
mingw32-sqlite - update to 3.26.0.0-2
mingw-sqlite (Red Hat package) - update to 3.26.0.0-2.el8_10
sqlite-doc - addressed in versions 3.26.0-20, 3.42.0-5
sqlite-libs - addressed in versions 3.26.0-20, 3.42.0-5
sqlite-devel - addressed in versions 3.26.0-20, 3.42.0-5
sqlite - addressed in versions 3.26.0-20, 3.42.0-5
lemon - addressed in versions 3.26.0-20, 3.42.0-5
sqlite-debugsource - addressed in versions 3.32.3-8, 3.37.2-8, 3.42.0-4
sqlite-help - addressed in versions 3.32.3-8, 3.37.2-8, 3.42.0-4
sqlite-devel - addressed in versions 3.32.3-8, 3.37.2-8, 3.42.0-4
sqlite-debuginfo - addressed in versions 3.32.3-8, 3.37.2-8, 3.42.0-4
sqlite - addressed in versions 3.32.3-8, 3.37.2-8, 3.42.0-4
sqlite-tcl - update to 3.42.0-5
sqlite-tools - update to 3.42.0-5
sqlite-analyzer - update to 3.42.0-5
sqlite - addressed in versions 3.46.1-4.fc41, 3.47.2-5.fc42
libsqlite3-0 - addressed in versions 3.50.2-9.41.1, 3.50.2-150000.3.33.1
libsqlite3-0-debuginfo - addressed in versions 3.50.2-9.41.1, 3.50.2-150000.3.33.1
libsqlite3-0-debuginfo-32bit - update to 3.50.2-9.41.1
libsqlite3-0-32bit - addressed in versions 3.50.2-9.41.1, 3.50.2-150000.3.33.1
sqlite3-debuginfo - addressed in versions 3.50.2-9.41.1, 3.50.2-150000.3.33.1
sqlite3 - addressed in versions 3.50.2-9.41.1, 3.50.2-150000.3.33.1
sqlite3-devel - addressed in versions 3.50.2-9.41.1, 3.50.2-150000.3.33.1
sqlite3-debugsource - addressed in versions 3.50.2-9.41.1, 3.50.2-150000.3.33.1
sqlite3-tcl - addressed in versions 3.50.2-9.41.1, 3.50.2-150000.3.33.1
sqlite3-tcl-debuginfo - update to 3.50.2-150000.3.33.1
libsqlite3-0-32bit-debuginfo - update to 3.50.2-150000.3.33.1
sqlite3-doc - update to 3.50.2-150000.3.33.1
Cryostat - update to 4.1.0
OpenShift Virtualization - update to 4.12.20
Red Hat OpenShift Container Platform - addressed in versions 4.12.82, 4.13.61, 4.14.55, 4.14.58, 4.15.56, 4.16.46, 4.17.37, 4.17.42, 4.18.22, 4.18.27, 4.19.7, 4.19.17, 4.20.0
rhel-- (Red Hat package) - update to 7/x86_64/21064/sqlite/3.7.17-9.el7_9.1/src/fd431d51/package">sqlite-3.7.17-9.el7_9.1
Red Hat Ceph Storage - update to 7.1
spice-client-win (Red Hat package) - addressed in versions 8.10-3.el8_2.1, 8.10-3.el8_4.1, 8.10-3.el8_6.1, 8.10-3.el8_8.1
IBM CICS TX Advanced - update to 10.1.0.0 ifix42
Red Hat build of Keycloak - update to 26.2.11
firefox - update to 140.8.0-1

External References

Related Security Bulletins