CVE-2026-39113: Buffer Overflow
Buffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil check-in 8bdc0d485e3ad0c7a1e818da66f106951d496b05cbe61d12c2c448f2f24b6d5d (Git mirror 169f68ed88b34cb68f720191c64c058f2ccec508, 2026-03-11) and later snapshots/builds allows an attacker to cause a denial of service via the ext/misc/sqlar.c, sqlarUncompressFunc(), sqlaruncompress(), sqlite3valueint64(), sqlite3malloc(int), uncompress() components
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/sqlite3to a version that resolves this vulnerability.Fixed in 3.40.1-2+deb12u2Fixed in 3.46.1-7+deb13u2Fixed in 3.53.4-2
Event History
Frequently Asked Questions
Which SQLite deployments are affected?
The issue affects source snapshots and builds that contain Fossil check-in 8bdc0d485e3ad0c7a1e818da66f106951d496b05cbe61d12c2c448f2f24b6d5d, mirrored in Git as 169f68ed88b34cb68f720191c64c058f2ccec508, and later snapshots/builds. The provided data does not identify affected release version numbers.
What must an attacker be able to do to trigger the issue?
The vulnerability is reachable through the SQL Archive extension implementation in ext/misc/sqlar.c, specifically its decompression handling. The provided data identifies denial of service as the impact but does not specify the required SQL privileges, input path, or whether the extension must be explicitly enabled.
What impact is confirmed?
An attacker can cause a denial of service through the buffer overflow in the sqlar decompression-related components. No confidentiality impact, data modification impact, or code-execution impact is stated in the provided data.