Executive brief
SQLite, a widely used database engine, contains a memory management flaw in its SQL expression parsing logic. By submitting a specially crafted SQL query, an attacker can cause the application to crash or potentially expose sensitive information stored in the system's memory. This could lead to service outages for applications relying on the database or the unauthorized disclosure of internal data.
Technical details
A use-after-free (CWE-416) vulnerability exists in SQLite 3.41 within the expression parsing logic in 'expr.c'. The root cause is located in the 'sqlite3ExprDelete' function, which releases a heap-allocated expression object but fails to nullify the pointer. Subsequent code paths dereference this dangling pointer to read internal flags and height values. An attacker capable of executing arbitrary SQL queries can trigger this flaw using nested compound expressions, resulting in a denial-of-service (segmentation fault) or information disclosure of heap memory. No official patch was available at the time of disclosure.
Affected products
- SQLite SQLite 3.41
Timeline
- 2026-07-27: advisory: CVE-2026-51300 published