CVE-2025-70873

NameCVE-2025-70873
DescriptionAn information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
sqlite3 (PTS)bullseye3.34.1-3vulnerable
bullseye (security)3.34.1-3+deb11u1vulnerable
bookworm3.40.1-2+deb12u2vulnerable
trixie3.46.1-7+deb13u1vulnerable
forky, sid3.46.1-9vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
sqlite3source(unstable)(unfixed)unimportant

Notes

https://sqlite.org/src/info/3d459f1fb1bd1b5e
https://sqlite.org/forum/forumpost/761eac3c82
https://gist.github.com/cnwangjihe/f496393f30f5ecec5b18c8f5ab072054
zipfile extension not build for Debian binary package builds

Search for package or bug name: Reporting problems