CVE-2025-7458

An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive information from process memory via a crafted SELECT statement with a large number of expressions in the ORDER BY clause.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sqlite:sqlite:*:*:*:*:*:*:*:*

History

11 Aug 2025, 19:11

Type Values Removed Values Added
References () https://sqlite.org/forum/forumpost/16ce2bb7a639e29b - () https://sqlite.org/forum/forumpost/16ce2bb7a639e29b - Issue Tracking
References () https://sqlite.org/src/info/12ad822d9b827777 - () https://sqlite.org/src/info/12ad822d9b827777 - Patch
Summary
  • (es) Un desbordamiento de entero en la función sqlite3KeyInfoFromExprList en las versiones 3.39.2 a 3.41.1 de SQLite permite a un atacante con la capacidad de ejecutar sentencias SQL arbitrarias para provocar una denegación de servicio o divulgar información confidencial de la memoria del proceso a través de una sentencia SELECT manipulada con una gran cantidad de expresiones en la cláusula ORDER BY.
First Time Sqlite
Sqlite sqlite
CPE cpe:2.3:a:sqlite:sqlite:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1

29 Jul 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-29 13:15

Updated : 2025-08-11 19:11


NVD link : CVE-2025-7458

Mitre link : CVE-2025-7458

CVE.ORG link : CVE-2025-7458


JSON object : View

Products Affected

sqlite

  • sqlite
CWE
CWE-190

Integer Overflow or Wraparound