An integer overflow exists in the FTS5 https://sqlite.org/fts5.html  extension. It occurs when the size of an array of tombstone pointers is calculated and truncated into a 32-bit integer. A pointer to partially controlled data can then be written out of bounds.
History

Mon, 08 Sep 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 08 Sep 2025 15:00:00 +0000

Type Values Removed Values Added
Description An integer overflow exists in the FTS5 https://sqlite.org/fts5.html  extension. It occurs when the size of an array of tombstone pointers is calculated and truncated into a 32-bit integer. A pointer to partially controlled data can then be written out of bounds.
Title Out Of Bounds write in FTS5 Extension in SQLite
Weaknesses CWE-190
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Google

Published:

Updated: 2025-09-08T15:10:31.923Z

Reserved: 2025-07-16T13:30:35.186Z

Link: CVE-2025-7709

cve-icon Vulnrichment

Updated: 2025-09-08T15:10:26.113Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-08T15:15:38.180

Modified: 2025-09-08T16:25:38.810

Link: CVE-2025-7709

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.