UbuntuUpdates.org

Package "sqlite3"

Name: sqlite3

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • LALR(1) Parser Generator for C or C++
  • SQLite 3 Tcl bindings
  • Command line interface for SQLite 3 (tools)

Latest version: 3.45.1-1ubuntu2.8
Release: noble (24.04)
Level: security
Repository: universe

Links



Other versions of "sqlite3" in Noble

Repository Area Version
base universe 3.45.1-1ubuntu2
base main 3.45.1-1ubuntu2
security main 3.45.1-1ubuntu2.8
updates main 3.45.1-1ubuntu2.8
updates universe 3.45.1-1ubuntu2.8

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 3.45.1-1ubuntu2.8 2026-09-16 20:07:54 UTC

sqlite3 (3.45.1-1ubuntu2.8) noble-security; urgency=medium

  * SECURITY UPDATE: buffer overflow via integer truncation in sqlar extension
    - debian/patches/CVE-2026-39113.patch: change sqlite3_value_int() to
      sqlite3_value_int64() in sqlarUncompressFunc() in ext/misc/sqlar.c to
      prevent 32-bit truncation of the decompressed size, which caused an
      undersized buffer allocation and heap buffer overflow via uncompress().
    - CVE-2026-39113

 -- Leonidas Da Silva Barbosa Thu, 03 Sep 2026 11:45:26 -0300

Source diff to previous version
CVE-2026-39113 Buffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil check-in 8bdc0d485e3ad0c7a1e818da66f106951d496b05c

Version: 3.45.1-1ubuntu2.7 2026-07-20 19:08:59 UTC
No changelog available yet.
Source diff to previous version

Version: 3.45.1-1ubuntu2.6 2026-06-29 18:07:38 UTC

  sqlite3 (3.45.1-1ubuntu2.6) noble-security; urgency=medium

  * SECURITY UPDATE: security issues in FTS5 full-text search
    - debian/patches/CVE-2026-11822_4.patch: Fix logic in ext/fts5/fts5_index.c.
    - CVE-2026-11822
    - CVE-2026-11824

 -- Marc Deslauriers <email address hidden> Tue, 16 Jun 2026 13:52:58 -0400

Source diff to previous version
CVE-2026-11822 SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes,
CVE-2026-11824 SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a cras

Version: 3.45.1-1ubuntu2.5 2025-09-15 19:08:17 UTC

  sqlite3 (3.45.1-1ubuntu2.5) noble-security; urgency=medium

  * SECURITY UPDATE: integer overflow in FTS5 extension
    - debian/patches/CVE-2025-7709.patch: optimize allocation of large
      tombstone arrays in fts5 in ext/fts5/fts5_index.c.
    - CVE-2025-7709

 -- Marc Deslauriers <email address hidden> Thu, 11 Sep 2025 14:06:42 -0400

Source diff to previous version
CVE-2025-7709 An integer overflow exists in the FTS5 https://sqlite.org/fts5.html  extension. It occurs when the size of an array of tombstone pointers is calcula

Version: 3.45.1-1ubuntu2.4 2025-07-28 18:07:40 UTC

  sqlite3 (3.45.1-1ubuntu2.4) noble-security; urgency=medium

  * SECURITY UPDATE: Memory corruption via number of aggregate terms
    - debian/patches/CVE-2025-6965.patch: raise an error right away if the
      number of aggregate terms in a query exceeds the maximum number of
      columns in src/expr.c, src/sqliteInt.h.
    - CVE-2025-6965

 -- Marc Deslauriers <email address hidden> Fri, 18 Jul 2025 10:56:16 -0400

CVE-2025-6965 There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This



About   -   Send Feedback to @ubuntu_updates