CVE-2025-7458

Severity CVSS v4.0:
MEDIUM
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
29/07/2025
Last modified:
11/08/2025

Description

An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive information from process memory via a crafted SELECT statement with a large number of expressions in the ORDER BY clause.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sqlite:sqlite:*:*:*:*:*:*:*:* 3.39.2 (including) 3.41.2 (excluding)