← back
CVE-2025-6965highCWE-197

Integer Truncation on SQLite

63Vexday Risk Score

Keep watching. It has a public proof of concept.

ssvc Attendcvss 7.2epss 73%
from disclosure to weapon267 days
Published on NVDJul 15
1st PoC+267d
exploitation probability
73%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Affected
3 products (9 components)
Red Hat Enterprise Linux 6 · Red Hat Enterprise Linux 7 · Red Hat OpenShift Container Platform 4
workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Fixed
52 products (1,151 components)
Red Hat Enterprise Linux AppStream (v. 9) · Red Hat Enterprise Linux BaseOS (v. 9) · Red Hat Enterprise Linux AppStream (v. 8) · Red Hat Enterprise Linux BaseOS (v. 8) · Red Hat Enterprise Linux BaseOS E4S (v.8.6) · and others 47
Not affected
10 products (141 components) — because the vulnerable code is not present in the product
Red Hat Advanced Cluster Security 4.7 · Red Hat Ceph Storage 8 · Red Hat Enterprise Linux 8 · Red Hat Enterprise Linux 9 · Red Hat Ceph Storage 7 · and others 5
There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/S:N/AU:N/R:U/V:D/RE:L/U:Green
Affected products
SQLite · SQLite
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.