Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Mageia 9: 2025-0167 moderate: sqlite3 denial of service issue

mageia
Calendar Grey May 27, 2025
Dist Mageia Esm H88
Versions of SQLite prior to 3.49.1, specifically 3.49.0, are vulnerable to a denial of service exploit; updated versions have been released to resolve this security concern.
In SQLite 3.49.0 before 3.49.1, certain argument values to sqlite3_db_config (in the C-language API) can cause a denial of service (application crash)

Summary

In SQLite 3.49.0 before 3.49.1, certain argument values to sqlite3_db_config (in the C-language API) can cause a denial of service (application crash). An sz*nBig multiplication is not cast to a 64-bit integer, and consequently some memory allocations may be incorrect. (CVE-2025-29088)

References

- https://bugs.mageia.org/show_bug.cgi?id=34217

-

- https://www.cve.org/CVERecord?id=CVE-2025-29088

Resolution

SRPMS

- 9/core/sqlite3-3.40.1-1.2.mga9

Publication date: 27 May 2025
URL: https://advisories.mageia.org/MGASA-2025-0167.html
Type: security
CVE: CVE-2025-29088

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here