Logo
vulnerabilityCVE-2026-11822
Name
CVE-2026-11822
Source
NVD ( link)Debian ( link)
Description
SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
sqlite
Exploitable

Vulnerability Ratings#


8.5
CVSSv4
7.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
master
3.53.2
Not Affected
openwrt
master
3.53.1-r1
Exploitable
openwrt
openwrt-25.12
3.53.1-r1
Exploitable