CVE-2025-7709

An integer overflow exists in the FTS5 https://sqlite.org/fts5.html  extension. It occurs when the size of an array of tombstone pointers is calculated and truncated into a 32-bit integer. A pointer to partially controlled data can then be written out of bounds.

GitHub Logohttps://github.com/l3montree-dev/devguard-action/issues/225
Open
LOW (1.8)

Add a comment

Mark as False Positive
Comment will be synced with https://github.com/l3montree-dev/devguard-action/issues/225
Last calculated at:

Affected component

debian/sqlite3

Installed version:
3.40.1
Fixed in:
no patch available

Management decisions across the organization

Copyright © 2025 L3montree GmbH and the DevGuard Contributors. All rights reserved. Version 2ab7b793efd72421aea8c3a994ac60202bf1b3a5