CVE Vulnerabilities

CVE-2025-6965

Numeric Truncation Error

Published: Jul 15, 2025 | Modified: Nov 04, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.7 IMPORTANT
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L
Ubuntu
MEDIUM

There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.

Weakness

Truncation errors occur when a primitive is cast to a primitive of a smaller size and data is lost in the conversion.

Affected Software

Name Vendor Start Version End Version
Sqlite Sqlite * 3.50.2 (excluding)
Red Hat Enterprise Linux 10 RedHat sqlite-0:3.46.1-5.el10_0 *
Red Hat Enterprise Linux 7 Extended Lifecycle Support RedHat sqlite-0:3.7.17-9.el7_9.1 *
Red Hat Enterprise Linux 8 RedHat nodejs:22-8100020250717142920.6d880403 *
Red Hat Enterprise Linux 8 RedHat sqlite-0:3.26.0-20.el8_10 *
Red Hat Enterprise Linux 8 RedHat mingw-sqlite-0:3.26.0.0-2.el8_10 *
Red Hat Enterprise Linux 8 RedHat sqlite-0:3.26.0-20.el8_10 *
Red Hat Enterprise Linux 8.2 Advanced Update Support RedHat sqlite-0:3.26.0-6.el8_2.1 *
Red Hat Enterprise Linux 8.2 Advanced Update Support RedHat spice-client-win-0:8.10-3.el8_2.1 *
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support RedHat sqlite-0:3.26.0-13.el8_4.1 *
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support RedHat spice-client-win-0:8.10-3.el8_4.1 *
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On RedHat sqlite-0:3.26.0-13.el8_4.1 *
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On RedHat spice-client-win-0:8.10-3.el8_4.1 *
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support RedHat sqlite-0:3.26.0-16.el8_6.3 *
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support RedHat spice-client-win-0:8.10-3.el8_6.1 *
Red Hat Enterprise Linux 8.6 Telecommunications Update Service RedHat sqlite-0:3.26.0-16.el8_6.3 *
Red Hat Enterprise Linux 8.6 Telecommunications Update Service RedHat spice-client-win-0:8.10-3.el8_6.1 *
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions RedHat sqlite-0:3.26.0-16.el8_6.3 *
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions RedHat spice-client-win-0:8.10-3.el8_6.1 *
Red Hat Enterprise Linux 8.8 Telecommunications Update Service RedHat sqlite-0:3.26.0-18.el8_8.2 *
Red Hat Enterprise Linux 8.8 Telecommunications Update Service RedHat spice-client-win-0:8.10-3.el8_8.1 *
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions RedHat sqlite-0:3.26.0-18.el8_8.2 *
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions RedHat spice-client-win-0:8.10-3.el8_8.1 *
Red Hat Enterprise Linux 9 RedHat nodejs:22-9060020250721113755.rhel9 *
Red Hat Enterprise Linux 9 RedHat sqlite-0:3.34.1-8.el9_6 *
Red Hat Enterprise Linux 9 RedHat sqlite-0:3.34.1-9.el9_7 *
Red Hat Enterprise Linux 9 RedHat sqlite-0:3.34.1-8.el9_6 *
Red Hat Enterprise Linux 9 RedHat sqlite-0:3.34.1-9.el9_7 *
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions RedHat sqlite-0:3.34.1-5.el9_0.1 *
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions RedHat sqlite-0:3.34.1-6.el9_2.2 *
Red Hat Enterprise Linux 9.4 Extended Update Support RedHat sqlite-0:3.34.1-7.el9_4.1 *
Red Hat OpenShift Container Platform 4.12 RedHat rhcos-412.86.202510291903-0 *
Red Hat OpenShift Container Platform 4.13 RedHat rhcos-413.92.202510150118-0 *
Red Hat OpenShift Container Platform 4.14 RedHat rhcos-414.92.202510211419-0 *
Red Hat OpenShift Container Platform 4.17 RedHat rhcos-417.94.202510112152-0 *
Red Hat OpenShift Container Platform 4.18 RedHat rhcos-418.94.202510230424-0 *
Red Hat OpenShift Container Platform 4.19 RedHat rhcos-4.19.9.6.202510140714-0 *
Red Hat OpenShift Container Platform 4.20 RedHat rhcos-4.20.9.6.202509251656-0 *
Red Hat Web Terminal 1.11 on RHEL 9 RedHat web-terminal/web-terminal-rhel9-operator:1.11-19 *
Red Hat Web Terminal 1.11 on RHEL 9 RedHat web-terminal/web-terminal-tooling-rhel9:1.11-8 *
Red Hat Web Terminal 1.12 on RHEL 9 RedHat web-terminal/web-terminal-tooling-rhel9:1.12-4 *
Cert-manager operator for Red Hat OpenShift 1.16 RedHat cert-manager/jetstack-cert-manager-rhel9:sha256:ec9c6b34a40da29f3ee89b361d94879025a998d34309bf3b63c555f3c225eb16 *
Compliance Operator 1 RedHat compliance/openshift-compliance-content-rhel8:sha256:79554e96e4780fe3c219058a2d6408aa08dda31de091b7b7a647ed5f939e4712 *
Compliance Operator 1 RedHat compliance/openshift-compliance-must-gather-rhel8:sha256:4953a7ea865ff38a4fe19d5536d8062870c262733c640a2c7e4bd9e0bfb3d498 *
Compliance Operator 1 RedHat compliance/openshift-compliance-openscap-rhel8:sha256:09f37fa618a4e02460b28b1097148573b395354300db5f917ed155ab7968b779 *
Compliance Operator 1 RedHat compliance/openshift-compliance-rhel8-operator:sha256:525c4d55fde92557bd0c3123961cb32eee28edca3aaa884e224d5efa4f3c4f83 *
File Integrity Operator 1 RedHat compliance/openshift-file-integrity-rhel8-operator:sha256:364d11af112a5b1d3f28c9ea8b7aac678e111b9c7fca0516d61036904f318605 *
Red Hat Advanced Cluster Security 4.7 RedHat advanced-cluster-security/rhacs-collector-rhel8:sha256:488e7716dc50df623f9088ee36120266d4db2637e2d2ce89810f1fdd8f2161f0 *
Red Hat AI Inference Server 3.2 RedHat rhaiis/vllm-cuda-rhel9:sha256:ec961e5acfde5c1ad0a7e0e2c86a0bf56b9bc46357fa124f9db6dff1006076ab *
Red Hat AI Inference Server 3.2 RedHat rhaiis/vllm-rocm-rhel9:sha256:7856bdb7ae0d643a7b9362c164d4d4fe3c0c7186f5fff73a7ae9835b3df52e57 *
Red Hat AI Inference Server 3.2 RedHat rhaiis/model-opt-cuda-rhel9:sha256:14e32e88f1b89f59ed34a6d712746b82a6a54c6ed4727784f18aeff853abbdc7 *
Red Hat Ceph Storage 7 RedHat rhceph/rhceph-7-rhel9:sha256:4d2f9dc5b2b33ee1c77bbfabcbbb9f4d94d343b04c4de2e4f8b3b81a1f0fd2fe *
Red Hat Ceph Storage 8 RedHat rhceph/rhceph-8-rhel9:sha256:75e6643866fa05fce50284a164d48533259c91be3fcac85556844a67e25887e9 *
Red Hat Discovery 2 RedHat discovery/discovery-server-rhel9:sha256:c517869dacaf4d3650310d4a52e83706e0b311d6ebb4a9b37b1c7acff5c142ec *
Red Hat Discovery 2 RedHat discovery/discovery-server-rhel9:sha256:b4683720677a1e45efbfd291d8b130b530642221e8a55a49e931e1b8b2c81ac3 *
Red Hat Discovery 2 RedHat discovery/discovery-ui-rhel9:sha256:69cb9c84b806ee2f448bdbbcf3174855432f5caec8f31ca2a345655da4a72f57 *
Red Hat Insights proxy 1.5 RedHat insights-proxy/insights-proxy-container-rhel9:sha256:e54a5a5f9d69dd6a03e2bcd845e2202910a188d266d4a79b12c387ceffc36f2d *
Red Hat Insights proxy 1.5 RedHat insights-proxy/insights-proxy-container-rhel9:sha256:345d8bc236043df01ce0557357d20fa443719dc943038f9648cfac0c5a465cfe *
Sqlite Ubuntu upstream *
Sqlite3 Ubuntu devel *
Sqlite3 Ubuntu esm-infra-legacy/trusty *
Sqlite3 Ubuntu esm-infra/bionic *
Sqlite3 Ubuntu esm-infra/focal *
Sqlite3 Ubuntu esm-infra/xenial *
Sqlite3 Ubuntu jammy *
Sqlite3 Ubuntu noble *
Sqlite3 Ubuntu plucky *
Sqlite3 Ubuntu questing *

Potential Mitigations

References