SQLite: Integer truncation in findOrCreateAggInfoColumn [CVE-2025-6965]


SQLite: Integer truncation in findOrCreateAggInfoColumn [CVE-2025-6965]

https://sqlite.org/cves.html lists CVE-2025-6965 as fixed in 3.50.2 (released 2025-06-28) with the description of "An attacker who can inject arbitrary SQL statements into an application might be able to cause an integer overflow resulting in a read off the end of an array." and points to https://sqlite.org/src/info/5508b56fd24016c1 for the fix. More recently, Google Security Research released their report at https://github.com/google/security-research/security/advisories/GHSA-qj7j-3jp8-8ccv which states:

Previous articleNext article

POPULAR CATEGORY

corporate

14387

entertainment

17632

research

8573

misc

17840

wellness

14464

athletics

18750