Critical Vulnerabilities in sqlite3 Affecting SUSE Systems

Critical Vulnerabilities in sqlite3 Affecting SUSE Systems

First seen 17 Jun 2026, 17:10 UTC Linuxsecuritybugzilla.suse.comUbuntu 81% similarity 72.0

Article Content

Browse articles
ThreatCluster

SUSE has released an important update addressing two critical vulnerabilities in sqlite3, specifically within the FTS5 full-text extension. CVE-2026-11822 involves memory corruption that could lead to process crashes, memory exhaustion, or arbitrary code execution. CVE-2026-11824 is a heap-based buffer overflow vulnerability that allows similar exploitative outcomes. Both vulnerabilities have a CVSS score of 7.8 from SUSE and 8.5 from NVD, indicating a high severity level. The vulnerabilities were published on June 9, 2026, and the update was released on June 15, 2026. Affected systems include sqlite2 and sqlite3, which are widely used in various applications. Users are advised to apply the patches immediately to mitigate potential risks.

Key Points: • Two critical vulnerabilities in sqlite3 have been identified, affecting SUSE systems. • CVE-2026-11822 and CVE-2026-11824 allow for process crashes and arbitrary code execution. • Patches were released on June 15, 2026, following the vulnerabilities' publication on June 9, 2026.

ThreatCluster AI How this analysis works

Timeline

2026-06-09
CVE-2026-11822 published
Memory corruption vulnerabilities in sqlite3's FTS5 extension disclosed, allowing crashes and code execution.
Linuxsecurity
2026-06-09
CVE-2026-11824 published
Heap-based buffer overflow vulnerability in sqlite3's FTS5 extension disclosed, enabling crashes and arbitrary code execution.
Linuxsecurity
2026-06-15
Patch released for sqlite3 vulnerabilities
SUSE released an important update to address the vulnerabilities in sqlite3, urging users to apply it immediately.
Linuxsecurity
2026-06-17
Vulnerabilities confirmed in Bugzilla
Details of CVE-2026-11822 and CVE-2026-11824 were confirmed in SUSE's Bugzilla, highlighting the risks involved.
bugzilla.suse.com

Community

Browse all →

Tracked Entities in This Story