← Vulnerability feed

Vulnerability record · CVE-2019-8457 · published 30 May 2019

CVE-2019-8457: SQLite rtreenode() heap out-of-bounds read on invalid rtree tables

Sqlite · Sqlite

SQLite versions 3.6.0 through 3.27.2 contain a heap out-of-bounds read in the rtreenode() function when it processes invalid rtree tables. The flaw is reachable over the network with no authentication or user interaction per the CVSS vector, and it affects SQLite as well as distributions that ship it such as Ubuntu, Fedora and openSUSE.

9.8 CVSS 3.1 Critical EPSS 45% · top 1.2% CWE-125 · Out-of-bounds read
9.8CVSS 3.1 base score, v2 7.5
45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
30References
17 Jun 2026Last modified by NVD

Description

SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tables.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityCVSS is 9.8 critical and EPSS is high, but there is no KEV listing, no documented ransomware use and no confirmed in-the-wild exploitation in the record.

What it is

SQLite versions 3.6.0 through 3.27.2 contain a heap out-of-bounds read in the rtreenode() function when it processes invalid rtree tables. The flaw is reachable over the network with no authentication or user interaction per the CVSS vector, and it affects SQLite as well as distributions that ship it such as Ubuntu, Fedora and openSUSE.

Impact

An attacker can trigger an out-of-bounds read, which may crash the process or leak adjacent heap memory. The CVSS vector rates confidentiality, integrity and availability impact as high, but the record does not describe a concrete code-execution path.

Attack surface

The CVSS vector is AV:N/AC:L/PR:N/UI:N, so it is reachable over the network without credentials or user interaction. In practice this depends on an application exposing SQLite rtree handling to untrusted input, which the record does not detail.

Exploitation

CVE-2019-8457 is not listed in CISA KEV and no ransomware use is documented. EPSS is 0.45426 (98.7th percentile), indicating high predicted exploitation activity, and references include patch and vendor advisory tags.

What to do

  • Upgrade SQLite to 3.28.0 or later, which contains the fix referenced in the vendor release notes and patch.
  • Apply the distribution updates for Ubuntu (USN-4004-1/2, USN-4019-1/2), Fedora, openSUSE and Oracle products listed in the references.
  • If immediate patching is not possible, restrict untrusted input from reaching SQLite rtree table handling in exposed applications.
  • Track vendor advisories for embedded SQLite copies in third-party products, since the record lists multiple affected vendors.

Detection

  • Monitor application and database logs for crashes or abnormal termination tied to SQLite rtree operations.
  • Watch for repeated malformed or invalid rtree table inputs reaching SQLite-backed services.
  • Use memory-safety tooling or sanitizers in test environments to catch out-of-bounds reads in rtreenode().

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00074.html Third Party Advisory
https://kc.mcafee.com/corporate/index?page=content&id=SB10365
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OPKYSWCOM3CL66RI76TYVIG
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SJPFGA45DI4F5MCF2OAACGH
https://security.netapp.com/advisory/ntap-20190606-0002/ Third Party Advisory
https://usn.ubuntu.com/4004-1/ Third Party Advisory
https://usn.ubuntu.com/4004-2/ Third Party Advisory
https://usn.ubuntu.com/4019-1/ Third Party Advisory
https://usn.ubuntu.com/4019-2/ Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2020.html
https://www.oracle.com/security-alerts/cpujan2020.html
https://www.oracle.com/security-alerts/cpujul2020.html
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html PatchThird Party Advisory
https://www.sqlite.org/releaselog/3_28_0.html Release NotesVendor Advisory
https://www.sqlite.org/src/info/90acdbfce9c08858 PatchVendor Advisory
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00074.html Third Party Advisory
https://kc.mcafee.com/corporate/index?page=content&id=SB10365
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OPKYSWCOM3CL66RI76TYVIG
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SJPFGA45DI4F5MCF2OAACGH
https://security.netapp.com/advisory/ntap-20190606-0002/ Third Party Advisory
https://usn.ubuntu.com/4004-1/ Third Party Advisory
https://usn.ubuntu.com/4004-2/ Third Party Advisory
https://usn.ubuntu.com/4019-1/ Third Party Advisory
https://usn.ubuntu.com/4019-2/ Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2020.html
https://www.oracle.com/security-alerts/cpujan2020.html
https://www.oracle.com/security-alerts/cpujul2020.html
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html PatchThird Party Advisory
https://www.sqlite.org/releaselog/3_28_0.html Release NotesVendor Advisory
https://www.sqlite.org/src/info/90acdbfce9c08858 PatchVendor Advisory

Track CVE-2019-8457 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2024-4577PHP-CGI on Windows argument injection leads to remote code executionPHP-CGI on Windows can misinterpret characters in the command line passed to Win32 API functions when certain code pages are configured, due to Windo…KEVEPSS 100%analysed9.8CVE-2021-44026Roundcube Webmail SQL injection via search parametersRoundcube Webmail before 1.3.17 and 1.4.x before 1.4.12 is prone to SQL injection through the search or search_params input. The flaw is remotely rea…KEVEPSS 70%analysed9.8CVE-2021-42013Apache HTTP Server path traversal and RCE via incomplete fixThe fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient, leaving a path traversal flaw that lets attackers map URLs to files outside…KEVEPSS 100%analysed9.8CVE-2021-41773Apache HTTP Server 2.4.49 path traversal and RCEA path normalization flaw introduced in Apache HTTP Server 2.4.49 lets attackers map URLs to files outside directories configured by Alias-like direc…KEVEPSS 100%analysed9.8CVE-2021-1870Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions, affecting macOS Big Sur, Catalina, Mojave, iOS and iPadOS, plus WebKitGTK a…KEVEPSS 7.7%analysed9.8CVE-2021-1871Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions. It affects macOS Big Sur, Catalina, Mojave, iOS and iPadOS, and a remote at…KEVEPSS 7.0%analysed9.8CVE-2020-16846SaltStack Salt API shell injection via crafted web requestsSaltStack Salt through 3002 is vulnerable to OS command injection when the SSH client is enabled and crafted web requests are sent to the Salt API. T…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2019-8457), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.