Bug 2487258 (CVE-2026-11822) - CVE-2026-11822 sqlite: SQLite: Arbitrary code execution via crafted FTS5 full-text search data
Summary: CVE-2026-11822 sqlite: SQLite: Arbitrary code execution via crafted FTS5 full...
Keywords:
Status: NEW
Alias: CVE-2026-11822
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2508048 2508049 2508050 2508051 2508052 2508053 2508056 2508047
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-06-09 20:01 UTC by OSIDB Bzimport
Modified: 2026-08-31 16:04 UTC (History)
22 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2026:59180 0 None None None 2026-08-24 21:57:43 UTC
Red Hat Product Errata RHBA-2026:59221 0 None None None 2026-08-24 22:42:34 UTC
Red Hat Product Errata RHBA-2026:59550 0 None None None 2026-08-25 17:43:14 UTC
Red Hat Product Errata RHBA-2026:60260 0 None None None 2026-08-26 11:02:01 UTC
Red Hat Product Errata RHBA-2026:60273 0 None None None 2026-08-26 11:56:29 UTC
Red Hat Product Errata RHBA-2026:60467 0 None None None 2026-08-27 10:52:53 UTC
Red Hat Product Errata RHBA-2026:60468 0 None None None 2026-08-27 10:54:37 UTC
Red Hat Product Errata RHBA-2026:60512 0 None None None 2026-08-27 13:08:48 UTC
Red Hat Product Errata RHBA-2026:61262 0 None None None 2026-08-31 02:14:47 UTC
Red Hat Product Errata RHBA-2026:61342 0 None None None 2026-08-31 09:06:10 UTC
Red Hat Product Errata RHSA-2026:54371 0 None None None 2026-08-12 14:17:34 UTC
Red Hat Product Errata RHSA-2026:54530 0 None None None 2026-08-13 11:34:59 UTC
Red Hat Product Errata RHSA-2026:55601 0 None None None 2026-08-17 11:58:58 UTC
Red Hat Product Errata RHSA-2026:55603 0 None None None 2026-08-17 14:33:40 UTC
Red Hat Product Errata RHSA-2026:58927 0 None None None 2026-08-24 13:05:43 UTC
Red Hat Product Errata RHSA-2026:58936 0 None None None 2026-08-24 15:03:58 UTC
Red Hat Product Errata RHSA-2026:58938 0 None None None 2026-08-24 13:06:34 UTC
Red Hat Product Errata RHSA-2026:58939 0 None None None 2026-08-24 11:15:49 UTC
Red Hat Product Errata RHSA-2026:59020 0 None None None 2026-08-24 14:17:55 UTC
Red Hat Product Errata RHSA-2026:59024 0 None None None 2026-08-24 14:12:36 UTC
Red Hat Product Errata RHSA-2026:59956 0 None None None 2026-08-26 07:38:40 UTC
Red Hat Product Errata RHSA-2026:61242 0 None None None 2026-08-31 02:22:08 UTC
Red Hat Product Errata RHSA-2026:61697 0 None None None 2026-08-31 16:04:19 UTC

Description OSIDB Bzimport 2026-06-09 20:01:38 UTC
SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database.

Comment 3 errata-xmlrpc 2026-08-12 14:17:33 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:54371 https://access.redhat.com/errata/RHSA-2026:54371

Comment 4 errata-xmlrpc 2026-08-13 11:34:58 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:54530 https://access.redhat.com/errata/RHSA-2026:54530

Comment 5 errata-xmlrpc 2026-08-17 11:58:58 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:55601 https://access.redhat.com/errata/RHSA-2026:55601

Comment 6 errata-xmlrpc 2026-08-17 14:33:39 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:55603 https://access.redhat.com/errata/RHSA-2026:55603

Comment 7 errata-xmlrpc 2026-08-24 11:15:48 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:58939 https://access.redhat.com/errata/RHSA-2026:58939

Comment 8 errata-xmlrpc 2026-08-24 13:05:42 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:58927 https://access.redhat.com/errata/RHSA-2026:58927

Comment 9 errata-xmlrpc 2026-08-24 13:06:33 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:58938 https://access.redhat.com/errata/RHSA-2026:58938

Comment 10 errata-xmlrpc 2026-08-24 14:12:35 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:59024 https://access.redhat.com/errata/RHSA-2026:59024

Comment 11 errata-xmlrpc 2026-08-24 14:17:54 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On

Via RHSA-2026:59020 https://access.redhat.com/errata/RHSA-2026:59020

Comment 12 errata-xmlrpc 2026-08-24 15:03:57 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:58936 https://access.redhat.com/errata/RHSA-2026:58936

Comment 13 errata-xmlrpc 2026-08-26 07:38:39 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:59956 https://access.redhat.com/errata/RHSA-2026:59956

Comment 14 errata-xmlrpc 2026-08-31 02:22:06 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:61242 https://access.redhat.com/errata/RHSA-2026:61242

Comment 15 errata-xmlrpc 2026-08-31 16:04:17 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:61697 https://access.redhat.com/errata/RHSA-2026:61697


Note You need to log in before you can comment on or make changes to this bug.