This update for sqlite3 fixes the following issues
Update to 3.53.2:
- CVE-2026-11822: memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause
process crashes, memory exhaustion, or arbitrary code execution (bsc#1268012).
- CVE-2026-11824: heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers
to cause a crash or execute arbitrary code (bsc#1268013).
Changes:
* Add the Query Result Formatter (QRF) library for formatting the
results of SQL queries for human readability on a fixed-pitch
font screen.
* Enhance ALTER TABLE to permit adding and removing NOT NULL and
CHECK constraints.
* The REINDEX EXPRESSIONS statement rebuilds expression indexes.
* The body of TEMP triggers may now modify and/or query tables
in the main schema.
* Enhance VACUUM INTO so that if a URI filename is used as the
target and that filename has a reserve=N query parameter with
N between 0 and 255, then...
Read the Full Advisory- openSUSE Leap 16.0:
lemon-3.53.2-160000.1.1
libsqlite3-0-3.53.2-160000.1.1
libsqlite3-0-x86-64-v3-3.53.2-160000.1.1
sqlite3-3.53.2-160000.1.1
sqlite3-devel-3.53.2-160000.1.1
sqlite3-doc-3.53.2-160000.1.1
sqlite3-tcl-3.53.2-160000.1.1
* bsc#1268012
* bsc#1268013
References:
* https://www.suse.com/security/cve/CVE-2026-11822.html
* https://www.suse.com/security/cve/CVE-2026-11824.html
Get the latest Linux and open source security news straight to your inbox.