Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Mageia reports two vulnerabilities in SQLite affecting versions 10 and 9, allowing denial of service and potential sensitive information disclosure due to NULL pointer dereference and malicious changeset handling.. Publication date: 28 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0305.html Type: security Affected Mageia releases: 10, 9 CVE: CVE-2026-50812, CVE-2026-50813 Description: CVE-2026-50812: A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows an attacker who can supply a malformed changeset blob to cause a denial of service. The issue occurs when sqlite3changeset_apply_v3() applies a corrupt changeset and reaches sqlite3_value_type() with a NULL sqlite3_value pointer. CVE-2026-50813: An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path. References: - https://bugs.mageia.org/show_bug.cgi?id=35988 - https://www.cve.org/CVERecord?id=CVE-2026-50812 - https://www.cve.org/CVERecord?id=CVE-2026-50813 - https://www.cve.org/CVERecord?id=CVE-2026-50812 - https://www.cve.org/CVERecord?id=CVE-2026-50813 SRPMS: - 10/core/sqlite3-3.51.3-1.2.mga10 - 9/core/sqlite3-3.40.1-1.10.mga9 . Mageia security update addresses NULL pointer issue and data leak risks in SQLite, enhancing system protection. Learn more.. SQLite Security, Mageia Advisory, Denial of Service, Local Attacker Risks, Session Extension. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.