Logo
vulnerabilityCVE-2025-7709
Name
CVE-2025-7709
Source
NVD ( link)Debian ( link)
Description
An integer overflow exists in the FTS5 https://sqlite.org/fts5.html  extension. It occurs when the size of an array of tombstone pointers is calculated and truncated into a 32-bit integer. A pointer to partially controlled data can then be written out of bounds.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
sqlite3
Patched

Vulnerability Ratings#


6.9
CVSSv4
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
yocto
kirkstone
3.38.5
Not Affected
yocto
master
3.53.2
Not Affected

Resolved with patches#


sqlite3 (yocto:scarthgap)

#
Title
Author
Resolve
1
Optimize allocation of large tombstone arrays in fts5.
Hugo SIMELIERE <simeliere.hugo@non.se.com>
CVE-2025-7709