Executive brief
SQLite is a widely used database engine embedded in countless applications and operating systems. A vulnerability in its full-text search feature (FTS5) could allow a malicious database file to crash an application or potentially run unauthorized code. This risk is most significant for software that processes untrusted database files provided by users.
Technical details
A heap-based buffer overflow exists in the FTS5 full-text search extension of SQLite due to an integer underflow in the fts5ChunkIterate() function. The vulnerability is triggered when processing a corrupted or maliciously crafted database containing continuation page metadata with a 'szLeaf' value smaller than 4. This causes an inflated remaining byte count during FTS5 MATCH query processing, leading to an out-of-bounds write of attacker-controlled data. The issue affects applications compiled with the SQLITE_ENABLE_FTS5 option. A fix is available in SQLite version 3.53.2.
Affected products
- SQLite SQLite < 3.53.2
Timeline
- 2026-05-11: patched: Fix committed to SQLite source tree
- 2026-06-03: patched: SQLite version 3.53.2 released
- 2026-06-09: advisory: CVE-2026-11824 published