SQLite: Integer truncation in findOrCreateAggInfoColumn [CVE-2025-6965]


SQLite: Integer truncation in findOrCreateAggInfoColumn [CVE-2025-6965]

https://sqlite.org/cves.html lists CVE-2025-6965 as fixed in 3.50.2 (released 2025-06-28) with the description of "An attacker who can inject arbitrary SQL statements into an application might be able to cause an integer overflow resulting in a read off the end of an array." and points to https://sqlite.org/src/info/5508b56fd24016c1 for the fix. More recently, Google Security Research released their report at https://github.com/google/security-research/security/advisories/GHSA-qj7j-3jp8-8ccv which states:

Previous articleNext article

POPULAR CATEGORY

corporate

14028

entertainment

17333

research

8282

misc

17809

wellness

14133

athletics

18416