CVE-2025-6965

Description

A memory corruption flaw was found in SQLite. Under specific conditions a query can be generated where the number of aggregate terms could exceed the number of columns available. This issue could lead to memory corruption and subsequent unintended behavior.

Statement

This vulnerability in SQLite is categorized as Important rather than Critical because, although it involves memory corruption, the conditions required to trigger it are relatively constrained. The flaw arises when a query causes the number of aggregate terms to exceed internal limits, leading to potential buffer overflows or memory mismanagement. However, exploitation requires the ability to craft complex SQL queries and interact with the SQLite engine in a specific manner—typically through direct SQL input. There is no known evidence of arbitrary code execution, privilege escalation, or remote exploitability as a direct result of this flaw. Additionally, most SQLite deployments are embedded in applications where input is tightly controlled or sanitized.

Mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score7.77.7N/A
Attack VectorNetworkNetworkN/A
Attack ComplexityHighHighN/A
Privileges RequiredLowLowN/A
User InteractionNoneNoneN/A
ScopeChangedChangedN/A
ConfidentialityLowLowN/A
Integrity ImpactHighHighN/A
Availability ImpactLowLowN/A

Vector

Red Hat: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L

NVD: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L

Red Hat CVSS v3 Score Explanation

The flaw involves improper bounds checking when handling aggregate terms in queries—specifically, the number of aggregates can exceed the number of columns allocated internally (AggInfo->aCol or aFunc), leading to memory corruption. However, the attack complexity is high (AC:H) because triggering this requires carefully crafting SQL queries that exceed internal aggregation limits (SQLITE_LIMIT_COLUMN), which are normally well within safe bounds for most applications. It also requires low privileges (PR:L), meaning an attacker must already have access to submit SQL—typically not possible in unauthenticated or sandboxed contexts. The scope is changed (S:C), as corruption could potentially affect the behavior of the host application embedding SQLite. However, the confidentiality impact is low (C:L), since memory corruption does not directly expose sensitive data, and availability is also low (A:L), as it may result in crashes but not guaranteed denial of service.

Understanding the Weakness (CWE)

Integrity

Technical Impact: Modify Memory

The true value of the data is lost and corrupted data is used.

Frequently Asked Questions

Want to get errata notifications? Sign up here.