Описание
In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compound SELECT statement.
Отчет
As per the upstream bug at https://www.sqlite.org/src/info/4722bdab08cb1 the flaw is in the error checking routine which is triggered only in debug builds. In release builds this is a no-op and therefore release builds are non-vulnerable. Red Hat packages are not vulnerable to this flaw (because we dont ship debug builds)
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 5 | sqlite | Not affected | ||
| Red Hat Enterprise Linux 6 | sqlite | Not affected | ||
| Red Hat Enterprise Linux 7 | sqlite | Not affected | ||
| Red Hat Enterprise Linux 8 | sqlite | Not affected | ||
| Red Hat Openshift Data Foundation 4.19 | registry.redhat.io/odf4/cephcsi-rhel9 | Fixed | RHSA-2025:16504 | 23.09.2025 |
| Red Hat Openshift Data Foundation 4.19 | registry.redhat.io/odf4/cephcsi-rhel9-operator | Fixed | RHSA-2025:16504 | 23.09.2025 |
| Red Hat Openshift Data Foundation 4.19 | registry.redhat.io/odf4/mcg-core-rhel9 | Fixed | RHSA-2025:16504 | 23.09.2025 |
| Red Hat Openshift Data Foundation 4.19 | registry.redhat.io/odf4/mcg-rhel9-operator | Fixed | RHSA-2025:16504 | 23.09.2025 |
| Red Hat Openshift Data Foundation 4.19 | registry.redhat.io/odf4/ocs-client-console-rhel9 | Fixed | RHSA-2025:16504 | 23.09.2025 |
| Red Hat Openshift Data Foundation 4.19 | registry.redhat.io/odf4/ocs-client-rhel9-operator | Fixed | RHSA-2025:16504 | 23.09.2025 |
Показывать по
Дополнительная информация
Статус:
EPSS
8.8 High
CVSS3
Связанные уязвимости
In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compound SELECT statement.
In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compound SELECT statement.
In SQLite through 3.31.1, the ALTER TABLE implementation has a use-aft ...
In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compound SELECT statement.
EPSS
8.8 High
CVSS3