CVE-2025-29088

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-29088
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-29088.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-29088
Aliases
Downstream
Related
Published
2025-04-10T14:15:27Z
Modified
2025-10-22T10:09:55.837254Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

In SQLite 3.49.0 before 3.49.1, certain argument values to sqlite3dbconfig (in the C-language API) can cause a denial of service (application crash). An sz*nBig multiplication is not cast to a 64-bit integer, and consequently some memory allocations may be incorrect.

References

Affected packages

Git / github.com/sqlite/sqlite

Affected ranges

Type
GIT
Repo
https://github.com/sqlite/sqlite
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

Other

cvs-to-fossil-cutover
experimental
fts3-refactor
major-relase
relase

same-as-3.*

same-as-3.35.3

version-3.*

version-3.10.0
version-3.11.0
version-3.11.1
version-3.12.0
version-3.13.0
version-3.14.0
version-3.15.0
version-3.16.0
version-3.19.0
version-3.19.1
version-3.19.2
version-3.21.0
version-3.22.0
version-3.23.0
version-3.23.1
version-3.24.0
version-3.25.0
version-3.26.0
version-3.27.0
version-3.28.0
version-3.29.0
version-3.30.0
version-3.31.0
version-3.31.1
version-3.32.0
version-3.32.1
version-3.33.0
version-3.34.0
version-3.35.0
version-3.35.1
version-3.35.2
version-3.36.0
version-3.37.0
version-3.38.0
version-3.39.0
version-3.40.0
version-3.41.0
version-3.42.0
version-3.43.0
version-3.44.0
version-3.45.0
version-3.46.0
version-3.47.0
version-3.48.0
version-3.49.0
version-3.6.10
version-3.6.15
version-3.7.10
version-3.7.11
version-3.7.12
version-3.7.12.1
version-3.7.13
version-3.7.14
version-3.7.15
version-3.7.16
version-3.7.16.1
version-3.7.16.2
version-3.7.17
version-3.7.2
version-3.7.4
version-3.7.5
version-3.7.6
version-3.7.6.1
version-3.7.7
version-3.7.8
version-3.7.9
version-3.8.0
version-3.8.1
version-3.8.10
version-3.8.10.1
version-3.8.11
version-3.8.11.1
version-3.8.2
version-3.8.3
version-3.8.4
version-3.8.4.1
version-3.8.5
version-3.8.6
version-3.8.7
version-3.8.7.1
version-3.8.8
version-3.8.9
version-3.9.0
version-3.9.1

Database specific

vanir_signatures

[
    {
        "source": "https://github.com/sqlite/sqlite/commit/56d2fd008b108109f489339f5fd55212bb50afd4",
        "target": {
            "function": "setupLookaside",
            "file": "src/main.c"
        },
        "signature_version": "v1",
        "deprecated": false,
        "id": "CVE-2025-29088-69bc8e80",
        "signature_type": "Function",
        "digest": {
            "function_hash": "5429052069220559463260089493636071609",
            "length": 2737.0
        }
    },
    {
        "source": "https://github.com/sqlite/sqlite/commit/56d2fd008b108109f489339f5fd55212bb50afd4",
        "target": {
            "file": "src/main.c"
        },
        "signature_version": "v1",
        "deprecated": false,
        "id": "CVE-2025-29088-feb7f724",
        "signature_type": "Line",
        "digest": {
            "line_hashes": [
                "39826769564372032825417142920266208978",
                "131744436590503758423334362165627665526",
                "156887614002996371651060072260617843233",
                "22136163177545101843723995456546001038",
                "159263920347785671602192097111218575962",
                "269888135610323103955213216169360149096",
                "100507046096844854820297547028498584049",
                "137860169083551923182255130981399545593",
                "169295985084664084716035143178358945038",
                "224581361444588764553703061731657690862",
                "254961715956719408494865708781294070951",
                "34367095266247901411946366506791138213",
                "85749957422984725276054991603402471436",
                "289160059118046469697642598445374425411",
                "264931618189465631739270240648043167270",
                "153711847611322404467672144729869832259",
                "88819407589660696616667168905306560324",
                "78310239316019648382233471021170002623",
                "309044393595509933975460334536793728981",
                "65788192120267222678882514538643449038",
                "195859394979415466483821601830902246210",
                "100976245618461176497342310742969343975",
                "157649672884947916678494037889427738783",
                "288640495902043871289867985079375707513",
                "321759326460408989197929602329010527698",
                "137397909491990842435116783858523105752",
                "48151367006986126524073095391989941746",
                "222700987374964209519243816746825526612"
            ],
            "threshold": 0.9
        }
    }
]