CVE-2026-11824

Public on 2026-06-09
Modified on 2026-06-17
Description
SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attackers can trigger an integer underflow in fts5ChunkIterate() causing an inflated remaining byte count during FTS5 MATCH query processing, leading to a heap buffer overflow of attacker-controlled data in applications compiled with SQLITE_ENABLE_FTS5.
Severity
Important severity
Important
See what this means
CVSS v3 Base Score
7.8
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2023 nodejs22 Pending Fix
Amazon Linux 2023 nodejs24 Pending Fix
Amazon Linux 2 - Core perl-DBD-SQLite Not Affected
Amazon Linux 2023 perl-DBD-SQLite Not Affected
Amazon Linux 2023 perl-DateTime-Format-SQLite Not Affected
Amazon Linux 2 - Core rust Not Affected
Amazon Linux 2023 rust Not Affected
Amazon Linux 2023 rust-cargo-c Not Affected
Amazon Linux 2 - Core sqlite Not Affected
Amazon Linux 2023 sqlite Pending Fix
Amazon Linux 2 - Core tcl Not Affected
Amazon Linux 2023 tcl Not Affected

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H