Vulnerability record · CVE-2019-8457 · published 30 May 2019
CVE-2019-8457: SQLite rtreenode() heap out-of-bounds read on invalid rtree tables
Sqlite · Sqlite
SQLite versions 3.6.0 through 3.27.2 contain a heap out-of-bounds read in the rtreenode() function when it processes invalid rtree tables. The flaw is reachable over the network with no authentication or user interaction per the CVSS vector, and it affects SQLite as well as distributions that ship it such as Ubuntu, Fedora and openSUSE.
Description
SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tables.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS is 9.8 critical and EPSS is high, but there is no KEV listing, no documented ransomware use and no confirmed in-the-wild exploitation in the record.
What it is
SQLite versions 3.6.0 through 3.27.2 contain a heap out-of-bounds read in the rtreenode() function when it processes invalid rtree tables. The flaw is reachable over the network with no authentication or user interaction per the CVSS vector, and it affects SQLite as well as distributions that ship it such as Ubuntu, Fedora and openSUSE.
Impact
An attacker can trigger an out-of-bounds read, which may crash the process or leak adjacent heap memory. The CVSS vector rates confidentiality, integrity and availability impact as high, but the record does not describe a concrete code-execution path.
Attack surface
The CVSS vector is AV:N/AC:L/PR:N/UI:N, so it is reachable over the network without credentials or user interaction. In practice this depends on an application exposing SQLite rtree handling to untrusted input, which the record does not detail.
Exploitation
CVE-2019-8457 is not listed in CISA KEV and no ransomware use is documented. EPSS is 0.45426 (98.7th percentile), indicating high predicted exploitation activity, and references include patch and vendor advisory tags.
What to do
- Upgrade SQLite to 3.28.0 or later, which contains the fix referenced in the vendor release notes and patch.
- Apply the distribution updates for Ubuntu (USN-4004-1/2, USN-4019-1/2), Fedora, openSUSE and Oracle products listed in the references.
- If immediate patching is not possible, restrict untrusted input from reaching SQLite rtree table handling in exposed applications.
- Track vendor advisories for embedded SQLite copies in third-party products, since the record lists multiple affected vendors.
Detection
- Monitor application and database logs for crashes or abnormal termination tied to SQLite rtree operations.
- Watch for repeated malformed or invalid rtree table inputs reaching SQLite-backed services.
- Use memory-safety tooling or sanitizers in test environments to catch out-of-bounds reads in rtreenode().
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-8457 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-8457), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.