Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Mageia SQLite Moderate NULL Pointer Denial of Service 2026-0305

mageia
Calendar Grey July 28, 2026
Scroller Mageia
Mageia security update addresses NULL pointer issue and data leak risks in SQLite, enhancing system protection. Learn more.
Mageia reports two vulnerabilities in SQLite affecting versions 10 and 9, allowing denial of service and potential sensitive information disclosure due to NULL pointer dereference ...

Summary

Description: CVE-2026-50812: A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows an attacker who can supply a malformed changeset blob to cause a denial of service. The issue occurs when sqlite3changeset_apply_v3() applies a corrupt changeset and reaches sqlite3_value_type() with a NULL sqlite3_value pointer.
CVE-2026-50813: An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path.

References

- https://bugs.mageia.org/show_bug.cgi?id=35988

- https://www.cve.org/CVERecord?id=CVE-2026-50812

- https://www.cve.org/CVERecord?id=CVE-2026-50813

- https://www.cve.org/CVERecord?id=CVE-2026-50812

- https://www.cve.org/CVERecord?id=CVE-2026-50813

Resolution

SRPMS

- 10/core/sqlite3-3.51.3-1.2.mga10

- 9/core/sqlite3-3.40.1-1.10.mga9

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 28 Jul 2026 
URL: https://advisories.mageia.org/MGASA-2026-0305.html
Type: security
CVE: CVE-2026-50812, CVE-2026-50813

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.