{"id":"SUSE-SU-2025:20561-1","summary":"Security update for sqlite3","details":"This update for sqlite3 fixes the following issues:\n\n- Update to 3.50.2:\n  * Fix the concat_ws() SQL function so that it includes empty\n    strings in the concatenation.\n  * Avoid writing frames with no checksums into the wal file if a\n    savepoint is rolled back after dirty pages have already been\n    spilled into the wal file.\n  * Fix the Bitvec object to avoid stack overflow when the\n    database is within 60 pages of its maximum size.\n  * Fix a problem with UPDATEs on fts5 tables that contain BLOB\n    values.\n  * Fix an issue with transitive IS constraints on a RIGHT JOIN.\n  * CVE-2025-6965: Fixed Integer Truncation in SQLite (bsc#1246597)\n  * Ensure that sqlite3_setlk_timeout() holds the database mutex.\n\n- Update to 3.50 (3.50.1):\n  * Improved handling and robust output of control characters\n  * sqlite3_rsync no longer requires WAL mode and needs less\n    bandwidth\n  * Bug fixes and optimized JSON handling\n  * Performance optimizations and developer visible fixes\n\n- Update to release 3.49.2:\n  * Fix a bug in the NOT NULL optimization of version 3.40.0 that\n    can lead to a memory error if abused.\n  * Fix the count-of-view optimization so that it does not give an\n    incorrect answer for a DISTINCT query.\n  * Fix a possible incorrect answer that can result if a UNIQUE\n    constraint of a table contains the PRIMARY KEY column and that\n    UNIQUE constraint is used by an IN operator.\n  * Fix obscure problems with the generate_series() extension\n    function.\n  * Incremental improvements to the configure/make.\n\n- Add subpackage for the lemon parser generator.\n","modified":"2026-03-12T02:04:43.908620Z","published":"2025-08-20T11:36:54Z","related":["CVE-2025-6965"],"upstream":["CVE-2025-6965"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2025/suse-su-202520561-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1246597"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-6965"}],"affected":[{"package":{"name":"sqlite3","ecosystem":"SUSE:Linux Micro 6.0","purl":"pkg:rpm/suse/sqlite3&distro=SUSE%20Linux%20Micro%206.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.50.2-1.1"}]}],"ecosystem_specific":{"binaries":[{"libsqlite3-0":"3.50.2-1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:20561-1.json"}}],"schema_version":"1.7.5"}