CVE Vulnerabilities

CVE-2025-6965

Numeric Truncation Error

Published: Jul 15, 2025 | Modified: Nov 04, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.7 IMPORTANT
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.

Weakness

Truncation errors occur when a primitive is cast to a primitive of a smaller size and data is lost in the conversion.

Affected Software

NameVendorStart VersionEnd Version
SqliteSqlite*3.50.2 (excluding)
Red Hat Enterprise Linux 10RedHatsqlite-0:3.46.1-5.el10_0*
Red Hat Enterprise Linux 7 Extended Lifecycle SupportRedHatsqlite-0:3.7.17-9.el7_9.1*
Red Hat Enterprise Linux 8RedHatnodejs:22-8100020250717142920.6d880403*
Red Hat Enterprise Linux 8RedHatsqlite-0:3.26.0-20.el8_10*
Red Hat Enterprise Linux 8RedHatmingw-sqlite-0:3.26.0.0-2.el8_10*
Red Hat Enterprise Linux 8RedHatsqlite-0:3.26.0-20.el8_10*
Red Hat Enterprise Linux 8.2 Advanced Update SupportRedHatsqlite-0:3.26.0-6.el8_2.1*
Red Hat Enterprise Linux 8.2 Advanced Update SupportRedHatspice-client-win-0:8.10-3.el8_2.1*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatsqlite-0:3.26.0-13.el8_4.1*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatspice-client-win-0:8.10-3.el8_4.1*
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnRedHatsqlite-0:3.26.0-13.el8_4.1*
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnRedHatspice-client-win-0:8.10-3.el8_4.1*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatsqlite-0:3.26.0-16.el8_6.3*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatspice-client-win-0:8.10-3.el8_6.1*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatsqlite-0:3.26.0-16.el8_6.3*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatspice-client-win-0:8.10-3.el8_6.1*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatsqlite-0:3.26.0-16.el8_6.3*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatspice-client-win-0:8.10-3.el8_6.1*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatsqlite-0:3.26.0-18.el8_8.2*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatspice-client-win-0:8.10-3.el8_8.1*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatsqlite-0:3.26.0-18.el8_8.2*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatspice-client-win-0:8.10-3.el8_8.1*
Red Hat Enterprise Linux 9RedHatnodejs:22-9060020250721113755.rhel9*
Red Hat Enterprise Linux 9RedHatsqlite-0:3.34.1-8.el9_6*
Red Hat Enterprise Linux 9RedHatsqlite-0:3.34.1-9.el9_7*
Red Hat Enterprise Linux 9RedHatsqlite-0:3.34.1-8.el9_6*
Red Hat Enterprise Linux 9RedHatsqlite-0:3.34.1-9.el9_7*
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsRedHatsqlite-0:3.34.1-5.el9_0.1*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatsqlite-0:3.34.1-6.el9_2.2*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatsqlite-0:3.34.1-7.el9_4.1*
Red Hat OpenShift Container Platform 4.12RedHatrhcos-412.86.202510291903-0*
Red Hat OpenShift Container Platform 4.13RedHatrhcos-413.92.202510150118-0*
Red Hat OpenShift Container Platform 4.14RedHatrhcos-414.92.202510211419-0*
Red Hat OpenShift Container Platform 4.17RedHatrhcos-417.94.202510112152-0*
Red Hat OpenShift Container Platform 4.18RedHatrhcos-418.94.202510230424-0*
Red Hat OpenShift Container Platform 4.19RedHatrhcos-4.19.9.6.202510140714-0*
Red Hat OpenShift Container Platform 4.20RedHatrhcos-4.20.9.6.202509251656-0*
Red Hat Web Terminal 1.11 on RHEL 9RedHatweb-terminal/web-terminal-rhel9-operator:1.11-19*
Red Hat Web Terminal 1.11 on RHEL 9RedHatweb-terminal/web-terminal-tooling-rhel9:1.11-8*
Red Hat Web Terminal 1.12 on RHEL 9RedHatweb-terminal/web-terminal-tooling-rhel9:1.12-4*
RHOSS-1.36-RHEL-8RedHatopenshift-serverless-1/logic-data-index-ephemeral-rhel8:1.36.0-11*
RHOSS-1.36-RHEL-8RedHatopenshift-serverless-1/logic-data-index-postgresql-rhel8:1.36.0-11*
RHOSS-1.36-RHEL-8RedHatopenshift-serverless-1/logic-db-migrator-tool-rhel8:1.36.0-11*
RHOSS-1.36-RHEL-8RedHatopenshift-serverless-1/logic-jobs-service-ephemeral-rhel8:1.36.0-10*
RHOSS-1.36-RHEL-8RedHatopenshift-serverless-1/logic-jobs-service-postgresql-rhel8:1.36.0-10*
RHOSS-1.36-RHEL-8RedHatopenshift-serverless-1/logic-kn-workflow-cli-artifacts-rhel8:1.36.0-4*
RHOSS-1.36-RHEL-8RedHatopenshift-serverless-1/logic-management-console-rhel8:1.36.0-9*
RHOSS-1.36-RHEL-8RedHatopenshift-serverless-1/logic-operator-bundle:1.36.0-12*
RHOSS-1.36-RHEL-8RedHatopenshift-serverless-1/logic-rhel8-operator:1.36.0-18*
RHOSS-1.36-RHEL-8RedHatopenshift-serverless-1/logic-swf-builder-rhel8:1.36.0-11*
RHOSS-1.36-RHEL-8RedHatopenshift-serverless-1/logic-swf-devmode-rhel8:1.36.0-7*
Cert-manager operator for Red Hat OpenShift 1.16RedHatcert-manager/jetstack-cert-manager-rhel9:sha256:df852ad92734bc087e213e6c7075daf6d7010db4ab72919649736804e295a6a2*
Compliance Operator 1RedHatcompliance/openshift-compliance-content-rhel8:sha256:7dfec9fbabaa748bbd91732ca5beebbd773306d5227a4f23af8fb0e444f0a779*
Compliance Operator 1RedHatcompliance/openshift-compliance-must-gather-rhel8:sha256:4953a7ea865ff38a4fe19d5536d8062870c262733c640a2c7e4bd9e0bfb3d498*
Compliance Operator 1RedHatcompliance/openshift-compliance-openscap-rhel8:sha256:06ad8599c4b0170264e40a45b0126504c87c37f0832265c7ff6541d2385b2049*
Compliance Operator 1RedHatcompliance/openshift-compliance-rhel8-operator:sha256:0903a7a5c857d96c84fd022e5785514eff201047e2fdd5d6699d79f17440ef02*
File Integrity Operator 1RedHatcompliance/openshift-file-integrity-rhel8-operator:sha256:59fcdf4ea159ba76fdb582011263672646dd9d63304a91592c0a21d0f43986a4*
Red Hat Advanced Cluster Security 4.7RedHatadvanced-cluster-security/rhacs-collector-rhel8:sha256:271dd3bfa99f1043d3ee885764fda7d3ba89c232025c1d3ad7fe45324f47473d*
Red Hat AI Inference Server 3.2RedHatrhaiis/vllm-cuda-rhel9:sha256:ec961e5acfde5c1ad0a7e0e2c86a0bf56b9bc46357fa124f9db6dff1006076ab*
Red Hat AI Inference Server 3.2RedHatrhaiis/vllm-rocm-rhel9:sha256:7856bdb7ae0d643a7b9362c164d4d4fe3c0c7186f5fff73a7ae9835b3df52e57*
Red Hat AI Inference Server 3.2RedHatrhaiis/model-opt-cuda-rhel9:sha256:dce6b0ea03379bf06664a5200af8b5f5ae3fad13cdce6d21873843f22554800b*
Red Hat AI Inference Server 3.2RedHatrhaiis/vllm-cuda-rhel9:sha256:dcb9d1cd005c40b6db6f893e56419e383b9dcc0d38315605cb1457e2af5354f7*
Red Hat AI Inference Server 3.2RedHatrhaiis/vllm-rocm-rhel9:sha256:53007894763e03f609c35c727cb738db3c2130b19fa0e1069c24240e0870fb7a*
Red Hat Ceph Storage 7RedHatrhceph/rhceph-7-rhel9:sha256:4d2f9dc5b2b33ee1c77bbfabcbbb9f4d94d343b04c4de2e4f8b3b81a1f0fd2fe*
Red Hat Ceph Storage 8RedHatrhceph/rhceph-8-rhel9:sha256:69c4edadc3bfd45dd982764b7f9d9a0f3a6d74d26a0443796aaa4a65455c62d1*
Red Hat Ceph Storage 8RedHatrhceph/rhceph-8-rhel9:sha256:c1c3e3e46bb57c2c99378b7336aa2c2015b7279dcb3df7fdccc8c3dee1522ba6*
Red Hat Discovery 2RedHatdiscovery/discovery-server-rhel9:sha256:c517869dacaf4d3650310d4a52e83706e0b311d6ebb4a9b37b1c7acff5c142ec*
Red Hat Discovery 2RedHatdiscovery/discovery-server-rhel9:sha256:97a1bb076f7f29a5f2b80c4724cb27c4e87f89c2d73a7719c44dc8c044329503*
Red Hat Discovery 2RedHatdiscovery/discovery-ui-rhel9:sha256:69cb9c84b806ee2f448bdbbcf3174855432f5caec8f31ca2a345655da4a72f57*
Red Hat Insights proxy 1.5RedHatinsights-proxy/insights-proxy-container-rhel9:sha256:c26d589f12647890b67aaa986f54d3f7c6f7f2563fb5a73f38d559e6138739d7*
Red Hat Insights proxy 1.5RedHatinsights-proxy/insights-proxy-container-rhel9:sha256:1d72e553fe5a7696e600dc8fd2fe9050ba1992fa190bea622134ca7bfce7bb0d*
SqliteUbuntuupstream*
Sqlite3Ubuntudevel*
Sqlite3Ubuntuesm-infra-legacy/trusty*
Sqlite3Ubuntuesm-infra/bionic*
Sqlite3Ubuntuesm-infra/focal*
Sqlite3Ubuntuesm-infra/xenial*
Sqlite3Ubuntujammy*
Sqlite3Ubuntunoble*
Sqlite3Ubuntuplucky*
Sqlite3Ubuntuquesting*

Potential Mitigations

References