MGASA-2026-0195

Source
https://advisories.mageia.org/MGASA-2026-0195.html
Import Source
https://advisories.mageia.org/MGASA-2026-0195.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2026-0195
Upstream
  • CVE-2025-70873
Published
2026-06-11T16:55:52Z
Modified
2026-06-11T17:00:04.551130756Z
Summary
Updated sqlite3 packages fix bug & security vulnerability
Details

sqlite3 shipped in Mageia 9 lacks ICU support. This update brings sqlite3-icu to allow ICU support be loaded as an optional extension. This update fixes CVE-2025-70873, an information disclosure issue. The zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.

References
Credits

Affected packages

Mageia:9 / sqlite3

Package

Name
sqlite3
Purl
pkg:rpm/mageia/sqlite3?arch=source&distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.40.1-1.8.mga9

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0195.json"