In SQLite 3.49.0 before 3.49.1, certain argument values to
sqlite3_db_config (in the C-language API) can cause a denial of service
(application crash). An sz*nBig multiplication is not cast to a 64-bit
integer, and consequently some memory allocations may be incorrect.
(CVE-2025-29088)
- https://bugs.mageia.org/show_bug.cgi?id=34217
-
- https://www.cve.org/CVERecord?id=CVE-2025-29088
- 9/core/sqlite3-3.40.1-1.2.mga9
Get the latest Linux and open source security news straight to your inbox.