Advisories ยป MGASA-2026-0305

Updated sqlite3 packages fix security vulnerabilities

Publication date: 28 Jul 2026
Modification date: 28 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-50812 , CVE-2026-50813

Description

CVE-2026-50812:
A NULL pointer dereference in the SQLite Session Extension in SQLite
3.53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows
an attacker who can supply a malformed changeset blob to cause a denial
of service. The issue occurs when sqlite3changeset_apply_v3() applies a
corrupt changeset and reaches sqlite3_value_type() with a NULL
sqlite3_value pointer.

CVE-2026-50813:
An issue in SQLite before Fossil check-in 869a51ae84df allows a local
attacker to obtain sensitive information via the Session Extension
changeset concat/changegroup merge path.
                

References

SRPMS

10/core

9/core