[CLSA-2026:1782142827] sqlite: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-06-22 15:40:43 UTC
Description:
- CVE-2026-11822: fix memory corruption in FTS5 fts5LeafRead() by rejecting leaf pages with szLeaf < 4, blocking the OOB read in fts5LeafSeek() - CVE-2026-11824: fix heap-based buffer overflow via integer underflow in fts5ChunkIterate() when szLeaf < 4 (same root cause; closed by the same fts5LeafRead validation tightening)
Updated packages:
  • lemon-3.26.0-19.el8.tuxcare.els2.x86_64.rpm
    sha:8b3df5eb20e9428d0e96ec0d7b0fa1bb0c410d29f9d976df1a8e8e43a032a8c9
  • sqlite-3.26.0-19.el8.tuxcare.els2.i686.rpm
    sha:06e2d22cdeda148c9464aaaa8cb962dbf34af49160f84b0cf87a3d3139c9b956
  • sqlite-3.26.0-19.el8.tuxcare.els2.x86_64.rpm
    sha:3ed2c2f47c58064f86e12aee5f3ba30d1a1ccd727faca1f8fb3d3fd678f391d5
  • sqlite-analyzer-3.26.0-19.el8.tuxcare.els2.x86_64.rpm
    sha:73fb9979bd71271f3cb244197964f35b5b338279a6c2ecd3131d7fde329f0040
  • sqlite-devel-3.26.0-19.el8.tuxcare.els2.i686.rpm
    sha:9c0f43e485e035c21cef237c92497f6157f442e82a85247603152d48a6a1472c
  • sqlite-devel-3.26.0-19.el8.tuxcare.els2.x86_64.rpm
    sha:ca824c516d98ba2d242471115ca31824f5078995523f089b9377c95d53c72f56
  • sqlite-doc-3.26.0-19.el8.tuxcare.els2.noarch.rpm
    sha:1bfb44fad51340a3c7bac1b181a72b97c1272fbb6312212fbf3c6016ca4ecb72
  • sqlite-libs-3.26.0-19.el8.tuxcare.els2.i686.rpm
    sha:3f3d2b4ebb192b7ee8fb905eb91e88c77d1050eaaaba9b72deaa729170443385
  • sqlite-libs-3.26.0-19.el8.tuxcare.els2.x86_64.rpm
    sha:494e26df37e3602113d26d04f2376f43facf563582f494166eba94ead1053262
  • sqlite-tcl-3.26.0-19.el8.tuxcare.els2.x86_64.rpm
    sha:40d16b2f0815a7a0d4a21341a7ee9b7d27b8d3738cdd7019e67234f483703126
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.