Alerts This Week
Warning Icon 1 1,213
Alerts This Week
Warning Icon 1 1,213

openSUSE sqlite3 Important Memory Corruption Issues 2026-21090-1

opensuse
Calendar Grey June 30, 2026
Dist Opensuse Esm H88
openSUSE's Important sqlite3 update addresses two security flaws and enhances functionality.
An update that solves 2 vulnerabilities and has 2 bug fixes can now be installed.

Description

This update for sqlite3 fixes the following issues

Update to 3.53.2:

- CVE-2026-11822: memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause

process crashes, memory exhaustion, or arbitrary code execution (bsc#1268012).

- CVE-2026-11824: heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers

to cause a crash or execute arbitrary code (bsc#1268013).

Changes:

* Add the Query Result Formatter (QRF) library for formatting the

results of SQL queries for human readability on a fixed-pitch

font screen.

* Enhance ALTER TABLE to permit adding and removing NOT NULL and

CHECK constraints.

* The REINDEX EXPRESSIONS statement rebuilds expression indexes.

* The body of TEMP triggers may now modify and/or query tables

in the main schema.

* Enhance VACUUM INTO so that if a URI filename is used as the

target and that filename has a reserve=N query parameter with

N between 0 and 255, then...

Read the Full Advisory

Patch

Package List

- openSUSE Leap 16.0:

lemon-3.53.2-160000.1.1

libsqlite3-0-3.53.2-160000.1.1

libsqlite3-0-x86-64-v3-3.53.2-160000.1.1

sqlite3-3.53.2-160000.1.1

sqlite3-devel-3.53.2-160000.1.1

sqlite3-doc-3.53.2-160000.1.1

sqlite3-tcl-3.53.2-160000.1.1

References

* bsc#1268012

* bsc#1268013

References:

* https://www.suse.com/security/cve/CVE-2026-11822.html

* https://www.suse.com/security/cve/CVE-2026-11824.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:21090-1
Rating: important
Affected Products: openSUSE Leap 16.0 -------------------------------------------------------------

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here