CVE Vulnerabilities

CVE-2026-50812

NULL Pointer Dereference

Published: Jul 08, 2026 | Modified: Jul 09, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
5.5 MODERATE
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows an attacker who can supply a malformed changeset blob to cause a denial of service. The issue occurs when sqlite3changeset_apply_v3() applies a corrupt changeset and reaches sqlite3_value_type() with a NULL sqlite3_value pointer.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Hardened ImagesRedHatsqlite-main-3.53.3-1.hum1*
SqliteUbuntuupstream*
Sqlite3Ubuntujammy*
Sqlite3Ubuntunoble*
Sqlite3Ubuntuquesting*
Sqlite3Ubunturesolute*
Sqlite3Ubuntuupstream*

Potential Mitigations

References