CVE-2025-29088
Publication date 10 April 2025
Last updated 22 May 2025
Ubuntu priority
In SQLite 3.49.0 before 3.49.1, certain argument values to sqlite3_db_config (in the C-language API) can cause a denial of service (application crash). An sz*nBig multiplication is not cast to a 64-bit integer, and consequently some memory allocations may be incorrect.
Status
Package | Ubuntu Release | Status |
---|---|---|
sqlite | 25.04 plucky | Not in release |
24.10 oracular | Not in release | |
24.04 LTS noble | Not in release | |
22.04 LTS jammy |
Needs evaluation
|
|
20.04 LTS focal |
Needs evaluation
|
|
18.04 LTS bionic |
Needs evaluation
|
|
16.04 LTS xenial |
Needs evaluation
|
|
14.04 LTS trusty |
Needs evaluation
|
|
sqlite3 | 25.04 plucky |
Fixed 3.46.1-3ubuntu0.1
|
24.10 oracular |
Fixed 3.46.1-1ubuntu0.2
|
|
24.04 LTS noble |
Fixed 3.45.1-1ubuntu2.3
|
|
22.04 LTS jammy |
Fixed 3.37.2-2ubuntu0.4
|
|
20.04 LTS focal |
Fixed 3.31.1-4ubuntu0.7
|
|
18.04 LTS bionic |
Needs evaluation
|
|
16.04 LTS xenial |
Needs evaluation
|
|
14.04 LTS trusty |
Needs evaluation
|
References
Related Ubuntu Security Notices (USN)
- USN-7528-1
- SQLite vulnerabilities
- 22 May 2025