UbuntuUpdates.org

Package "sqlite3"

Name: sqlite3

Description:

Command line interface for SQLite 3

Latest version: 3.37.2-2ubuntu0.8
Release: jammy (22.04)
Level: updates
Repository: main
Homepage: https://www.sqlite.org/

Links


Download "sqlite3"


Other versions of "sqlite3" in Jammy

Repository Area Version
base main 3.37.2-2
base universe 3.37.2-2
security universe 3.37.2-2ubuntu0.8
security main 3.37.2-2ubuntu0.8
updates universe 3.37.2-2ubuntu0.8

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 3.37.2-2ubuntu0.8 2026-09-17 00:07:37 UTC

sqlite3 (3.37.2-2ubuntu0.8) jammy-security; urgency=medium

  * SECURITY UPDATE: buffer overflow via integer truncation in sqlar extension
    - debian/patches/CVE-2026-39113.patch: change sqlite3_value_int() to
      sqlite3_value_int64() in sqlarUncompressFunc() in ext/misc/sqlar.c to
      prevent 32-bit truncation of the decompressed size, which caused an
      undersized buffer allocation and heap buffer overflow via uncompress().
    - CVE-2026-39113

 -- Leonidas Da Silva Barbosa Thu, 03 Sep 2026 11:45:28 -0300

Source diff to previous version
CVE-2026-39113 Buffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil check-in 8bdc0d485e3ad0c7a1e818da66f106951d496b05c

Version: 3.37.2-2ubuntu0.7 2026-07-20 21:08:41 UTC
No changelog available yet.
Source diff to previous version

Version: 3.37.2-2ubuntu0.6 2026-06-29 21:07:33 UTC

  sqlite3 (3.37.2-2ubuntu0.6) jammy-security; urgency=medium

  * SECURITY UPDATE: security issues in FTS5 full-text search
    - debian/patches/CVE-2026-11822_4.patch: Fix logic in ext/fts5/fts5_index.c.
    - CVE-2026-11822
    - CVE-2026-11824

 -- Marc Deslauriers <email address hidden> Tue, 16 Jun 2026 13:53:33 -0400

Source diff to previous version
CVE-2026-11822 SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes,
CVE-2026-11824 SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a cras

Version: 3.37.2-2ubuntu0.5 2025-07-28 22:06:54 UTC

  sqlite3 (3.37.2-2ubuntu0.5) jammy-security; urgency=medium

  * SECURITY UPDATE: Memory corruption via number of aggregate terms
    - debian/patches/CVE-2025-6965.patch: raise an error right away if the
      number of aggregate terms in a query exceeds the maximum number of
      columns in src/expr.c, src/sqliteInt.h.
    - CVE-2025-6965

 -- Marc Deslauriers <email address hidden> Fri, 18 Jul 2025 11:17:24 -0400

Source diff to previous version
CVE-2025-6965 There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This

Version: 3.37.2-2ubuntu0.4 2025-05-22 21:07:41 UTC

  sqlite3 (3.37.2-2ubuntu0.4) jammy-security; urgency=medium

  * SECURITY UPDATE: DoS via sqlite3_db_config arguments
    - debian/patches/CVE-2025-29088.patch: harden SQLITE_DBCONFIG_LOOKASIDE
      interface against misuse in src/main.c, src/sqlite.h.in.
    - CVE-2025-29088

 -- Marc Deslauriers <email address hidden> Tue, 29 Apr 2025 12:38:50 -0400

CVE-2025-29088 In SQLite 3.49.0 before 3.49.1, certain argument values to sqlite3_db_config (in the C-language API) can cause a denial of service (application crash



About   -   Send Feedback to @ubuntu_updates