CVE-2026-11824
Public on 2026-06-09
Modified on 2026-06-17
Description
SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attackers can trigger an integer underflow in fts5ChunkIterate() causing an inflated remaining byte count during FTS5 MATCH query processing, leading to a heap buffer overflow of attacker-controlled data in applications compiled with SQLITE_ENABLE_FTS5.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2023 | nodejs22 | Pending Fix | ||
| Amazon Linux 2023 | nodejs24 | Pending Fix | ||
| Amazon Linux 2 - Core | perl-DBD-SQLite | Not Affected | ||
| Amazon Linux 2023 | perl-DBD-SQLite | Not Affected | ||
| Amazon Linux 2023 | perl-DateTime-Format-SQLite | Not Affected | ||
| Amazon Linux 2 - Core | rust | Not Affected | ||
| Amazon Linux 2023 | rust | Not Affected | ||
| Amazon Linux 2023 | rust-cargo-c | Not Affected | ||
| Amazon Linux 2 - Core | sqlite | Not Affected | ||
| Amazon Linux 2023 | sqlite | Pending Fix | ||
| Amazon Linux 2 - Core | tcl | Not Affected | ||
| Amazon Linux 2023 | tcl | Not Affected |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 7.8 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |