An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive information from process memory via a crafted SELECT statement with a large number of expressions in the ORDER BY clause.
History

Wed, 30 Jul 2025 06:30:00 +0000

Type Values Removed Values Added
First Time appeared Sqlite
Sqlite sqlite
Vendors & Products Sqlite
Sqlite sqlite

Wed, 30 Jul 2025 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L'}

threat_severity

Moderate


Tue, 29 Jul 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Jul 2025 13:15:00 +0000

Type Values Removed Values Added
Description An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive information from process memory via a crafted SELECT statement with a large number of expressions in the ORDER BY clause.
Title SQLite integer overflow in key info allocation may lead to information disclosure.
Weaknesses CWE-190
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Google

Published: 2025-07-29T12:43:19.427Z

Updated: 2025-07-29T13:30:52.617Z

Reserved: 2025-07-11T10:05:23.293Z

Link: CVE-2025-7458

cve-icon Vulnrichment

Updated: 2025-07-29T13:30:50.276Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-29T13:15:28.953

Modified: 2025-07-29T14:14:29.590

Link: CVE-2025-7458

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-07-29T12:43:19Z

Links: CVE-2025-7458 - Bugzilla