Bug 2487269 (CVE-2026-11824)

Summary: CVE-2026-11824 sqlite: SQLite: Arbitrary code execution and crash via heap-based buffer overflow in FTS5
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: akhatavk, alinfoot, aos-team-art-private, asdas, bbrownin, Daniel.McGovern, dpaolell, dtrifiro, jdelft, jupierce, lgarciaa, mbiarnes, ppalepu, ppostler, prdhamdh, rbryant, rhel-process-autobot, sghai, sidsharm, suppawar, vlaad, watson-tool-maintainers, weaton
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in SQLite, specifically within its FTS5 full-text search extension. Attackers can exploit a heap-based buffer overflow by providing a specially crafted database. This crafted database contains malicious metadata that triggers an integer underflow during FTS5 MATCH query processing. Successful exploitation of this vulnerability can lead to a crash of the application or allow for arbitrary code execution.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2508054, 2508055, 2508057, 2508059, 2508060, 2508061, 2508062, 2508058    
Bug Blocks:    

Description OSIDB Bzimport 2026-06-09 20:02:42 UTC
SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attackers can trigger an integer underflow in fts5ChunkIterate() causing an inflated remaining byte count during FTS5 MATCH query processing, leading to a heap buffer overflow of attacker-controlled data in applications compiled with SQLITE_ENABLE_FTS5.

Comment 3 errata-xmlrpc 2026-08-12 14:17:30 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:54371 https://access.redhat.com/errata/RHSA-2026:54371

Comment 4 errata-xmlrpc 2026-08-13 11:34:55 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:54530 https://access.redhat.com/errata/RHSA-2026:54530

Comment 5 errata-xmlrpc 2026-08-17 11:58:59 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:55601 https://access.redhat.com/errata/RHSA-2026:55601

Comment 6 errata-xmlrpc 2026-08-17 14:34:00 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:55603 https://access.redhat.com/errata/RHSA-2026:55603

Comment 7 errata-xmlrpc 2026-08-24 11:15:48 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:58939 https://access.redhat.com/errata/RHSA-2026:58939

Comment 8 errata-xmlrpc 2026-08-24 13:05:42 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:58927 https://access.redhat.com/errata/RHSA-2026:58927

Comment 9 errata-xmlrpc 2026-08-24 13:06:37 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:58938 https://access.redhat.com/errata/RHSA-2026:58938

Comment 10 errata-xmlrpc 2026-08-24 14:12:37 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:59024 https://access.redhat.com/errata/RHSA-2026:59024

Comment 11 errata-xmlrpc 2026-08-24 14:17:56 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On

Via RHSA-2026:59020 https://access.redhat.com/errata/RHSA-2026:59020

Comment 12 errata-xmlrpc 2026-08-24 15:03:58 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:58936 https://access.redhat.com/errata/RHSA-2026:58936

Comment 13 errata-xmlrpc 2026-08-26 07:38:39 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:59956 https://access.redhat.com/errata/RHSA-2026:59956

Comment 14 errata-xmlrpc 2026-08-31 16:04:22 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:61697 https://access.redhat.com/errata/RHSA-2026:61697

Comment 15 errata-xmlrpc 2026-09-01 18:59:30 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:62232 https://access.redhat.com/errata/RHSA-2026:62232

Comment 16 errata-xmlrpc 2026-09-01 19:12:08 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:62236 https://access.redhat.com/errata/RHSA-2026:62236

Comment 17 errata-xmlrpc 2026-09-02 07:31:32 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:62416 https://access.redhat.com/errata/RHSA-2026:62416

Comment 18 Jon Orris 2026-09-15 09:19:12 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.22

Via RHSA-2026:66357 https://access.redhat.com/errata/RHSA-2026:66357

Comment 19 Jon Orris 2026-09-17 07:15:17 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.12

Via RHSA-2026:65907 https://access.redhat.com/errata/RHSA-2026:65907

Comment 20 Jon Orris 2026-09-17 07:56:45 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.18

Via RHSA-2026:65851 https://access.redhat.com/errata/RHSA-2026:65851

Comment 21 Jon Orris 2026-09-17 17:11:35 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.13

Via RHSA-2026:65839 https://access.redhat.com/errata/RHSA-2026:65839