Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.2
CVE-2025-6965: SQLite database corruption risk if using outdated version
Exploitation likelihood: 73%
CVE-2025-6965
GHSA-2m69-gcr7-jv3q
GHSA-2m69-gcr7-jv3q
CVE-2025-6965
Summary
Outdated SQLite versions can cause database corruption if too many data values are processed together. This can lead to data loss or errors. To fix, update to the latest SQLite version, 3.50.2 or higher, to ensure database integrity.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | sqlite | sqlite |
< 3.50.2 cpe:2.3:a:sqlite:sqlite:*:*:*:*:*:*:*:* |
| nuget | – | sqlitepclraw.lib.e_sqlite3 | <= 2.1.11 |
| nuget | – | sqlitepclraw.lib.e_sqlite3.android | <= 2.1.11 |
| nuget | – | sqlitepclraw.lib.e_sqlite3.ios | <= 2.1.11 |
| Bitnami | – | sqlite | All versions |
| – | apple | macos |
< 26.0.0 cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* |
| – | apple | tvos |
< 26.0.0 cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* |
| – | apple | visionos |
< 26.0.0 cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:* |
| – | apple | watchos |
< 26.0.0 cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* |
| – | apple | ipados |
< 26.0.0 cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* |
| – | apple | iphone_os |
< 26.0.0 cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
| – | siemens | ruggedcom_crossbow |
< 5.8 cpe:2.3:a:siemens:ruggedcom_crossbow:*:*:*:*:*:*:*:* |
| – | siemens | sidis_prime |
< 4.0.800 cpe:2.3:a:siemens:sidis_prime:*:*:*:*:*:*:*:* |
Original title
SQLitePCLRaw.lib.e_sqlite3 has a vulnerable dependency on SQLite
Original description
There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.
nvd CVSS3.1
9.8
nvd CVSS4.0
7.2
Vulnerability type
CWE-197
- https://www.sqlite.org/src/info/5508b56fd24016c13981ec280ecdd833007c9d8dd595edb2... Patch
- http://seclists.org/fulldisclosure/2025/Sep/49
- http://seclists.org/fulldisclosure/2025/Sep/53
- http://seclists.org/fulldisclosure/2025/Sep/56
- http://seclists.org/fulldisclosure/2025/Sep/57
- http://seclists.org/fulldisclosure/2025/Sep/58
- http://www.openwall.com/lists/oss-security/2025/09/06/1
- https://nvd.nist.gov/vuln/detail/CVE-2025-6965
- https://cert-portal.siemens.com/productcert/html/ssa-225816.html
- https://cert-portal.siemens.com/productcert/html/ssa-485750.html
- https://github.com/google/security-research/security/advisories/GHSA-qj7j-3jp8-8...
- https://github.com/github/advisory-database/pull/7675
- https://github.com/advisories/GHSA-2m69-gcr7-jv3q
- https://github.com/ericsink/SQLitePCL.raw Product
Published: 15 Jul 2025 · Updated: 4 Jul 2026 · First seen: 7 Mar 2026