Bug 2487258 (CVE-2026-11822)

Summary: CVE-2026-11822 sqlite: SQLite: Arbitrary code execution via crafted FTS5 full-text search data
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: akhatavk, alinfoot, aos-team-art-private, asdas, bbrownin, Daniel.McGovern, dpaolell, dtrifiro, jdelft, jupierce, lgarciaa, mbiarnes, ppalepu, ppostler, prdhamdh, rbryant, rhel-process-autobot, sghai, sidsharm, suppawar, vlaad, watson-tool-maintainers, weaton
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in SQLite's FTS5 full-text search extension. This vulnerability involves memory corruption, specifically an out-of-bounds read and a heap buffer overflow, which can be triggered by supplying a crafted database with malformed FTS5 page data. When an FTS5 MATCH query is executed against such a database, an attacker can cause process crashes, memory exhaustion, or achieve arbitrary code execution, potentially compromising the system.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2508048, 2508049, 2508050, 2508051, 2508052, 2508053, 2508056, 2508047    
Bug Blocks:    

Description OSIDB Bzimport 2026-06-09 20:01:38 UTC
SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database.

Comment 3 errata-xmlrpc 2026-08-12 14:17:33 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:54371 https://access.redhat.com/errata/RHSA-2026:54371

Comment 4 errata-xmlrpc 2026-08-13 11:34:58 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:54530 https://access.redhat.com/errata/RHSA-2026:54530

Comment 5 errata-xmlrpc 2026-08-17 11:58:58 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:55601 https://access.redhat.com/errata/RHSA-2026:55601

Comment 6 errata-xmlrpc 2026-08-17 14:33:39 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:55603 https://access.redhat.com/errata/RHSA-2026:55603

Comment 7 errata-xmlrpc 2026-08-24 11:15:48 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:58939 https://access.redhat.com/errata/RHSA-2026:58939

Comment 8 errata-xmlrpc 2026-08-24 13:05:42 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:58927 https://access.redhat.com/errata/RHSA-2026:58927

Comment 9 errata-xmlrpc 2026-08-24 13:06:33 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:58938 https://access.redhat.com/errata/RHSA-2026:58938

Comment 10 errata-xmlrpc 2026-08-24 14:12:35 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:59024 https://access.redhat.com/errata/RHSA-2026:59024

Comment 11 errata-xmlrpc 2026-08-24 14:17:54 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On

Via RHSA-2026:59020 https://access.redhat.com/errata/RHSA-2026:59020

Comment 12 errata-xmlrpc 2026-08-24 15:03:57 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:58936 https://access.redhat.com/errata/RHSA-2026:58936

Comment 13 errata-xmlrpc 2026-08-26 07:38:39 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:59956 https://access.redhat.com/errata/RHSA-2026:59956

Comment 14 errata-xmlrpc 2026-08-31 02:22:06 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:61242 https://access.redhat.com/errata/RHSA-2026:61242

Comment 15 errata-xmlrpc 2026-08-31 16:04:17 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:61697 https://access.redhat.com/errata/RHSA-2026:61697

Comment 16 errata-xmlrpc 2026-09-01 18:59:29 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:62232 https://access.redhat.com/errata/RHSA-2026:62232

Comment 17 errata-xmlrpc 2026-09-01 19:12:09 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:62236 https://access.redhat.com/errata/RHSA-2026:62236

Comment 18 errata-xmlrpc 2026-09-02 07:31:30 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:62416 https://access.redhat.com/errata/RHSA-2026:62416