CVE-2025-7709

An integer overflow exists in the FTS5 https://sqlite.org/fts5.html  extension. It occurs when the size of an array of tombstone pointers is calculated and truncated into a 32-bit integer. A pointer to partially controlled data can then be written out of bounds.

Open
LOW (1.8)
  • logo

    System detected CVE-2025-7709 with a risk of 1.8

Add a comment

Mark as False Positive
Last calculated at:

Affected component

debian/sqlite3

Installed version:
3.40.1
Fixed in:
no patch available

Management decisions across the organization

Copyright © 2025 L3montree GmbH and the DevGuard Contributors. All rights reserved. Version 2ab7b793efd72421aea8c3a994ac60202bf1b3a5