Out-of-bounds read in SQLite - CVE-2023-7104
Published: January 4, 2024
Vulnerability details
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition within the sessionReadRecord() function in ext/session/sqlite3session.c when processing a corrupt changeset. A remote user can send a specially crafted request to trigger an out-of-bounds read error and read contents of memory on the system or perform a denial of service attack.
Affected software
Amazon Linux AMI
IBM AIX
Fedora
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Brocade Fabric OS
Ubuntu
openEuler
IBM VIOS
Red Hat OpenShift Serverless
OpenShift Service Mesh
OpenShift Container Platform for Windows Containers
Multicluster Engine for Kubernetes
OpenShift Virtualization
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat OpenShift Builds
Migration Toolkit for Runtimes
Service Telemetry Framework
Service Interconnect
Cryostat
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
OpenShift Logging
Submariner
Multicluster GlobalHub
Run Once Duration Override Operator for Red Hat OpenShift
Custom Metrics Autoscaler Operator for Red Hat OpenShift
Red Hat OpenShift distributed tracing (RHOSDT)
APEX Cloud Platform for Red Hat OpenShift
Red Hat OpenShift Dev Spaces
Use Case Manager App
App Connect Enterprise Certified Container
Red Hat Migration Toolkit for Applications
Tivoli Composite Application Manager for Transactions
IBM Security Verify Governance
Red Hat OpenStack
NetWorker
Telemetry Dashboard
Liquidware
webMethods Managed File Transfer
Citrix Workspace App
Webex App VDI
PowerVault ME5
APEX Cloud Platform for Microsoft Azure
OpenManage Network Integration (OMNI)
Enterprise SONiC
Storage Resource Manager
Storage Ceph
Wyse Device Agent
OpenShift API for Data Protection (OADP)
Network Observability plugin for the Openshift Console
SmartFabric Storage Software
PowerProtect Cyber Recovery
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Nessus Network Monitor
VMware Horizon Client
Red Hat OpenShift GitOps
IBM Qradar SIEM
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libsqlite3-tcl (Ubuntu package)
libsqlite3-dev (Ubuntu package)
libsqlite3-0 (Ubuntu package)
sqlite3 (Ubuntu package)
polkit
sqlite (Red Hat package)
sqlite-doc
sqlite-libs
sqlite-devel
sqlite
lemon
sqlite-debuginfo
sqlite-debugsource
sqlite-help
sqlite-analyzer
sqlite-tcl
sqlite-tools
nss
mozilla-crashreporter-firefox-debuginfo
firefox-debuginfo
firefox-debugsource
firefox
chromium
Cisco Jabber
Cisco Webex Meetings
Dell EMC Storage Monitoring and Reporting (SMR)
Juniper Secure Analytics (JSA)
How to mitigate CVE-2023-7104
Red Hat OpenShift Serverless - addressed in versions 1.31.1, 1.32.0
Red Hat OpenShift Builds - update to 1.0.1
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
Migration Toolkit for Runtimes - addressed in versions 1.2.4, 1.2.5
OpenShift API for Data Protection (OADP) - update to 1.3.1
SmartFabric Storage Software - update to 1.4.3
Service Telemetry Framework - update to 1.5.4
Service Interconnect - addressed in versions 1.5.3, 1.5.4
Migration Toolkit for Containers - addressed in versions 1.7.15, 1.8.3, 1.8.4
Red Hat OpenShift GitOps - addressed in versions 1.10.0, 1.10.4, 1.11, 1.11.3, 1.12.0, 1.12.5, 1.13.1
OpenShift Service Mesh - addressed in versions 2.4.8, 2.5.1, 2.5.2
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.8.5, 2.9.2, 2.9.3, 2.10.5, 2.10.8, 2.11.4, 2.11.7, 2.12.0, 2.12.1, 2.12.3
Red Hat Advanced Cluster Security for Kubernetes - update to 4.2.4
Red Hat OpenShift Container Platform - addressed in versions 4.11.59, 4.12.53, 4.13.45, 4.14.32, 4.14.33, 4.15.2, 4.15.3, 4.16.15, 4.16.44, 4.17.0
Nessus Network Monitor - update to 6.5.3
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
IBM Qradar SIEM - update to 7.5.0 Update Pack 8
OpenShift Container Platform for Windows Containers - addressed in versions 8.1.2, 9.0.1, 10.15.0
Brocade Fabric OS - addressed in versions 9.2.0c, 9.2.1a1, 9.2.2
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
PowerProtect Cyber Recovery - update to 19.18.0.2
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
libsqlite3-tcl (Ubuntu package) - update to Ubuntu Pro
libsqlite3-dev (Ubuntu package) - update to Ubuntu Pro
libsqlite3-0 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 3.31.1-4ubuntu0.6, 3.37.2-2ubuntu0.3, 3.40.1-1ubuntu0.1, 3.42.0-1ubuntu0.1
sqlite3 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
Submariner - update to 0.18.5
polkit - update to 0.117-11
Multicluster GlobalHub - addressed in versions 1.0.2, 1.2.1
Run Once Duration Override Operator for Red Hat OpenShift - update to 1.1.1
PowerVault ME5 - update to 1.2.2.1
APEX Cloud Platform for Microsoft Azure - update to 01.04.01.00
Network Observability plugin for the Openshift Console - update to 1.5.0
Multicluster Engine for Kubernetes - addressed in versions 2.5.8, 2.6.4, 2.6.7, 2.7.2, 2.7.4
Custom Metrics Autoscaler Operator for Red Hat OpenShift - update to 2.12.1-376
Red Hat OpenShift distributed tracing (RHOSDT) - update to 3.1.0
APEX Cloud Platform for Red Hat OpenShift - update to 03.04.01.00
OpenManage Network Integration (OMNI) - update to 3.7
Red Hat OpenShift Dev Spaces - addressed in versions 3.15.0, 3.16.0, 3.17.0
sqlite (Red Hat package) - addressed in versions 3.26.0-16.el8_6.2, 3.26.0-18.el8_8.1, 3.26.0-19.el8_9, 3.34.1-6.el9_2.1
sqlite-doc - addressed in versions 3.26.0-19, 3.42.0-4
sqlite-libs - addressed in versions 3.26.0-19, 3.42.0-4
sqlite-devel - addressed in versions 3.26.0-19, 3.42.0-4
sqlite - addressed in versions 3.26.0-19, 3.42.0-4
lemon - addressed in versions 3.26.0-19, 3.42.0-4
sqlite - update to 3.32.3-7
sqlite-devel - update to 3.32.3-7
sqlite-debuginfo - update to 3.32.3-7
sqlite-debugsource - update to 3.32.3-7
sqlite-help - update to 3.32.3-7
sqlite - update to 3.40.0-1
sqlite-analyzer - update to 3.42.0-4
sqlite-tcl - update to 3.42.0-4
sqlite-tools - update to 3.42.0-4
nss - update to 3.90.0-3
Use Case Manager App - update to 4.0.0
Enterprise SONiC - update to 4.4.1
OpenShift Virtualization - update to 4.14.6
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.15.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 5.0.2.2
Storage Resource Manager - update to 5.0.2.2
App Connect Enterprise Certified Container - addressed in versions 5.0.15, 11.3.0
Red Hat Migration Toolkit for Applications - update to 6.2
Storage Ceph - update to 7.0z1
Tivoli Composite Application Manager for Transactions - update to 7.4.0.2.24
Juniper Secure Analytics (JSA) - update to 7.5.0 UP11 IF03
IBM Security Verify Governance - update to 10.0.2.0.4
Wyse Device Agent - update to 14.6.10.18
Red Hat OpenStack - addressed in versions 16.2, 17.1
NetWorker - update to 19.10.0.3
mozilla-crashreporter-firefox-debuginfo - update to 79.0-15
firefox-debuginfo - update to 79.0-15
firefox-debugsource - update to 79.0-15
firefox - update to 79.0-15
chromium - addressed in versions 120.0.6099.199-1.el7, 120.0.6099.199-1.el8, 120.0.6099.199-1.el9, 120.0.6099.199-1.fc38, 120.0.6099.199-1.fc39
External References
Related Security Bulletins
- Out-of-bounds read in SQLite
- Ubuntu update for sqlite3
- Fedora 39 update for chromium
- Fedora 38 update for chromium
- Fedora EPEL 8 update for chromium
- Fedora EPEL 9 update for chromium
- Fedora EPEL 7 update for chromium
- Red Hat Enterprise Linux 8 update for sqlite
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.9
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.2
- Multiple vulnerabilities in Red Hat build of Cryostat 2 on RHEL 8
- Red Hat Enterprise Linux 8.8 Extended Update Support update for sqlite
- Multiple vulnerabilities in Migration Toolkit for Runtimes 1.2
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.8
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in Red Hat Network Observability
- Multiple vulnerabilities in Red Hat Multicluster GlobalHub
- Multiple vulnerabilities in Red Hat Openshift distributed tracing
- Multiple vulnerabilities in Red Hat OpenShift for Windows Containers 10.15
- Multiple vulnerabilities in Red Hat Migration Toolkit for Applications
- Multiple vulnerabilities in IBM App Connect Enterprise Certified Container
- openEuler update for firefox
- openEuler update for sqlite
- Red Hat Enterprise Linux 9.2 Extended Update Support update for sqlite
- Red Hat Enterprise Linux 8.6 Extended Update Support update for sqlite
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift for Windows Containers 9.0
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.15
- Multiple vulnerabilities in Red Hat OpenShift GitOps
- Multiple vulnerabilities in Red Hat OpenShift GitOps
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift GitOps
- Multiple vulnerabilities in Red Hat OpenShift support for Windows Containers 8.1
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.11
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Red Hat OpenShift Builds
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.9
- Multiple vulnerabilities in Logging Subsystem 5.7 for Red Hat OpenShift for RHEL 8
- Multiple vulnerabilities in Custom Metrics Autoscaler Operator for Red Hat OpenShift
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP) 1.3
- Multiple vulnerabilities in Red Hat Service Interconnect 1.5
- Multiple vulnerabilities in Migration Toolkit for Runtimes 1.2
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers (MTC) 1.8
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh Containers 2.5
- Multiple vulnerabilities in Service Telemetry Framework 1.5
- Multiple vulnerabilities in Red Hat OpenShift GitOps
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.10
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers (MTC) 1.7
- Out-of-bounds read in IBM AIX and IBM VIOS
- Multiple vulnerabilities in Dell NetWorker
- Multiple vulnerabilities in Dell ThinOS
- Multiple vulnerabilities in OpenShift Virtualization 4.14
- Multiple vulnerabilities in OpenShift Service Mesh 2.5
- Multiple vulnerabilities in OpenShift Service Mesh 2.4
- Multiple vulnerabilities in Red Hat OpenStack 16.2 packages
- Multiple vulnerabilities in Red Hat OpenStack 17.1 packages
- Multiple vulnerabilities in Service Interconnect 1.5
- Ubuntu update for sqlite3
- Multiple vulnerabilities in Run Once Duration Override Operator for Red Hat OpenShift 1.1
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.13
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.12
- Out-of-bounds read in IBM Storage Ceph
- Amazon Linux AMI update for polkit
- Amazon Linux AMI update for nss
- Amazon Linux AMI update for sqlite
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.10
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Migration Toolkit for Containers 1.8
- IBM Tivoli Composite Application Manager for Transactions (Response Time) update for SQLite
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in IBM Security Verify Governance - Identity Manager
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.12
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces 3.17
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.7
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.12
- Multiple vulnerabilities in IBM Use Case Manager App
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.6
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.11
- Multiple vulnerabilities in Enterprise SONiC Distribution
- Multiple vulnerabilities in Brocade Fabric OS
- Multiple vulnerabilities in Dell OpenManage Network Integration (OMNI)
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.5
- Multiple vulnerabilities in Multicluster GlobalHub 1.2
- Anolis OS update for sqlite
- Anolis OS update for sqlite
- Dell SmartFabric Storage Software update for third-party components
- Dell Wyse Device Agent update for third-party components
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.7
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.12
- Multiple vulnerabilities in IBM webMethods Managed File Transfer
- Dell APEX Cloud Platform for Microsoft Azure update for third-party components
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.10
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.6
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.11
- Multiple vulnerabilities in Submariner 0.18
- Juniper Secure Analytics update for third-party components
- Dell APEX Cloud Platform for Red Hat OpenShift update for third-party components
- Multiple vulnerabilities in Dell PowerProtect Cyber Recovery
- Multiple vulnerabilities in Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Tenable Network Monitor update for third-party components
- Multiple vulnerabilities in Dell PowerVault ME5