USN-7676-1: SQLite vulnerability
USN-7676-1: SQLite vulnerability
Publication date: 28 July 2025
Overview: SQLite could be made to crash or run programs if it received specially crafted input.
Packages
sqlite3 - C library that implements an SQL database engine
Details
It was discovered that SQLite incorrectly handled certain numbers of
aggregate terms. An attacker could use this issue to cause SQLite to crash,
resulting in a denial of service, or possibly execute arbitrary code.
The problem can be corrected by updating your system to the following package versions:
- 25.04 plucky: libsqlite3-0 – 3.46.1-3ubuntu0.2
- 24.04 noble: libsqlite3-0 – 3.45.1-1ubuntu2.4
- 22.04 jammy: libsqlite3-0 – 3.37.2-2ubuntu0.5