Executive brief
SQLite is a widely used database library embedded in countless applications and operating systems. A memory safety flaw in how it handles specific database queries could allow an attacker to crash an application, steal sensitive information from memory, or potentially take control of the affected system. This occurs when the database processes a specially crafted command containing an unusually long list of sorting instructions.
Technical details
A use-after-free (UAF) vulnerability exists in SQLite 3.41 within the ORDER BY clause parsing logic in 'expr.c'. The vulnerability is triggered when the parser processes a SQL statement with an excessively long list of ORDER BY terms, causing it to call 'sqlite3ExprListDelete()' to free an 'ExprList' structure without subsequently nulling the pointer. The code then immediately attempts to access the 'nExpr' member of this deallocated object. An attacker capable of executing arbitrary SQL can exploit this dangling pointer to cause a heap-use-after-free, potentially leading to application crashes, leakage of heap memory contents, or arbitrary code execution via heap spraying.
Affected products
- SQLite SQLite 3.41
Timeline
- 2026-07-27: disclosed
- 2026-07-27: advisory