Vulnerability record · CVE-2025-6965 · published 15 July 2025
CVE-2025-6965: SQLite aggregate term count mismatch memory corruption
Sqlite · Sqlite
SQLite versions before 3.50.2 allow the number of aggregate terms to exceed the number of available columns, leading to memory corruption. The flaw affects SQLite itself and downstream products embedding it, including Apple operating systems and Siemens industrial products. Because SQLite is widely embedded, the reachable attack surface depends on how each host application exposes SQL processing.
Description
There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:
Automated analysis
high priorityCVSS 4.0 rates it 7.2 HIGH with high integrity impact and a very high EPSS percentile, though exploitation is not confirmed in KEV and requires high complexity and some privilege.
What it is
SQLite versions before 3.50.2 allow the number of aggregate terms to exceed the number of available columns, leading to memory corruption. The flaw affects SQLite itself and downstream products embedding it, including Apple operating systems and Siemens industrial products. Because SQLite is widely embedded, the reachable attack surface depends on how each host application exposes SQL processing.
Impact
An attacker who can supply crafted SQL can trigger memory corruption, with the CVSS vector indicating high integrity impact and low confidentiality and availability impact. The practical gain depends on the host application's memory layout and privileges.
Attack surface
The CVSS 4.0 vector is network-reachable (AV:N) with low privileges required (PR:L) and no user interaction (UI:N), but high attack complexity (AC:H) and a passive attack requirement (AT:P). This suggests the flaw is reached through SQL processing in a networked service rather than by direct unauthenticated input.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented. EPSS is high at 0.72547 (99.4th percentile), but the only reference tag present is Patch and Third Party Advisory, so no public exploit code is confirmed by this record.
What to do
- Upgrade SQLite to 3.50.2 or later; the patch reference is the authoritative fix.
- For Apple and Siemens products, apply the vendor advisories that bundle the updated SQLite library.
- Inventory embedded SQLite copies in applications and appliances, since patching the OS package alone may not cover statically linked builds.
- Restrict network access to services that accept SQL input and enforce least privilege on database accounts.
- Where immediate upgrade is not possible, limit untrusted users' ability to submit arbitrary SQL to affected components.
Detection
- Monitor for crashes or abnormal termination in processes that embed SQLite, especially those parsing externally supplied SQL.
- Look for SQL statements with unusually large numbers of aggregate terms relative to the selected columns in application or database logs.
- Track version strings of SQLite libraries in use across hosts and flag any below 3.50.2.
- Correlate network-facing SQL endpoints with post-request memory error or sanitizer alerts where available.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.sqlite.org/src/info/5508b56fd24016c13981ec280ecdd833007c9d8dd595edb295b984c2b487b5c8 | Patch |
| http://seclists.org/fulldisclosure/2025/Sep/49 | Third Party Advisory |
| http://seclists.org/fulldisclosure/2025/Sep/53 | Third Party Advisory |
| http://seclists.org/fulldisclosure/2025/Sep/56 | Third Party Advisory |
| http://seclists.org/fulldisclosure/2025/Sep/57 | Third Party Advisory |
| http://seclists.org/fulldisclosure/2025/Sep/58 | Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2025/09/06/1 | Third Party Advisory |
| https://cert-portal.siemens.com/productcert/html/ssa-225816.html | Third Party Advisory |
| https://cert-portal.siemens.com/productcert/html/ssa-485750.html | Third Party Advisory |
Track CVE-2025-6965 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-6965), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.