{"id":"SUSE-SU-2026:21173-1","summary":"Security update for sqlite3","details":"This update for sqlite3 fixes the following issues:\n\nUpdate sqlite3 to version 3.51.3:\n\nSecurity issues:\n\n- CVE-2025-7709: Integer Overflow in FTS5 Extension (bsc#1254670).\n- CVE-2025-70873: SQLite zipfile extension may disclose uninitialized heap memory during inflation (bsc#1259619).\n\nNon security issue:\n\n- sqlite3 won't build when using --with icu (bsc#1248586).\n\nChangelog:\n\nUpdate to version 3.51.3:\n * Fix the WAL-reset database corruption bug:\n   https://sqlite.org/wal.html#walresetbug\n * Other minor bug fixes.\n\nUpdate to version 3.51.2:\n\n * Fix an obscure deadlock in the new broken-posix-lock detection\n   logic.\n * Fix multiple problems in the EXISTS-to-JOIN optimization.\n\nUpdate to version 3.51.1:\n * Fix incorrect results from nested EXISTS queries caused by the\n   optimization in item 6b in the 3.51.0 release.\n * Fix a latent bug in fts5vocab virtual table, exposed by new\n   optimizations in the 3.51.0 release\n\nUpdate to version 3.51.0:\n * New macros in sqlite3.h:\n - SQLITE_SCM_BRANCH -\u003e the name of the branch from which the\n source code is taken.\n - SQLITE_SCM_TAGS -\u003e space-separated list of tags on the source\n code check-in.\n - SQLITE_SCM_DATETIME -\u003e ISO-8601 date and time of the source\n * Two new JSON functions, jsonb_each() and jsonb_tree() work the\n same as the existing json_each() and json_tree() functions\n except that they return JSONB for the \"value\" column when the\n \"type\" is 'array' or 'object'.\n * The carray and percentile extensions are now built into the\n amalgamation, though they are disabled by default and must be\n activated at compile-time using the -DSQLITE_ENABLE_CARRAY\n and/or -DSQLITE_ENABLE_PERCENTILE options, respectively.\n * Enhancements to TCL Interface:\n - Add the -asdict flag to the eval command to have it set the\n row data as a dict instead of an array.\n - User-defined functions may now break to return an SQL NULL.\n * CLI enhancements:\n - Increase the precision of \".timer\" to microseconds.\n - Enhance the \"box\" and \"column\" formatting modes to deal with\n double-wide characters.\n - The \".imposter\" command provides read-only imposter tables\n that work with VACUUM and do not require the --unsafe-testing\n option.\n - Add the --ifexists option to the CLI command-line option and\n to the .open command.\n - Limit columns widths set by the \".width\" command to 30,000 or\n less, as there is not good reason to have wider columns, but\n supporting wider columns provides opportunity to malefactors.\n * Performance enhancements:\n - Use fewer CPU cycles to commit a read transaction.\n - Early detection of joins that return no rows due to one or\n more of the tables containing no rows.\n - Avoid evaluation of scalar subqueries if the result of the\n subquery does not change the result of the overall expression.\n - Faster window function queries when using\n \"BETWEEN :x FOLLOWING AND :y FOLLOWING\" with a large :y.\n * Add the PRAGMA wal_checkpoint=NOOP; command and the\n SQLITE_CHECKPOINT_NOOP argument for sqlite3_wal_checkpoint_v2().\n * Add the sqlite3_set_errmsg() API for use by extensions.\n * Add the sqlite3_db_status64() API, which works just like the\n existing sqlite3_db_status() API except that it returns 64-bit\n results.\n * Add the SQLITE_DBSTATUS_TEMPBUF_SPILL option to the\n sqlite3_db_status() and sqlite3_db_status64() interfaces.\n * In the session extension add the sqlite3changeset_apply_v3()\n interface.\n * For the built-in printf() and the format() SQL function, omit\n the leading '-' from negative floating point numbers if the '+'\n flag is omitted and the \"#\" flag is present and all displayed\n digits are '0'. Use '%#f' or similar to avoid outputs like\n '-0.00' and instead show just '0.00'.\n * Improved error messages generated by FTS5.\n * Enforce STRICT typing on computed columns.\n * Improved support for VxWorks\n * JavaScript/WASM now supports 64-bit WASM. The canonical builds\n continue to be 32-bit but creating one's own 64-bit build is\n now as simple as running \"make\".\n * Improved resistance to database corruption caused by an\n application breaking Posix advisory locks using close().\n","modified":"2026-04-22T20:09:46.877490Z","published":"2026-04-10T18:50:16Z","related":["CVE-2025-70873","CVE-2025-7709"],"upstream":["CVE-2025-70873","CVE-2025-7709"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202621173-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1248586"},{"type":"REPORT","url":"https://bugzilla.suse.com/1252217"},{"type":"REPORT","url":"https://bugzilla.suse.com/1254670"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259619"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-70873"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-7709"}],"affected":[{"package":{"name":"sqlite3","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/sqlite3&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.51.3-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"libsqlite3-0":"3.51.3-160000.1.1","sqlite3-devel":"3.51.3-160000.1.1","sqlite3-doc":"3.51.3-160000.1.1","sqlite3-tcl":"3.51.3-160000.1.1","sqlite3":"3.51.3-160000.1.1","libsqlite3-0-x86-64-v3":"3.51.3-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:21173-1.json"}},{"package":{"name":"sqlite3","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/sqlite3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.51.3-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"sqlite3-devel":"3.51.3-160000.1.1","sqlite3-doc":"3.51.3-160000.1.1","sqlite3-tcl":"3.51.3-160000.1.1","sqlite3":"3.51.3-160000.1.1","libsqlite3-0-x86-64-v3":"3.51.3-160000.1.1","libsqlite3-0":"3.51.3-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:21173-1.json"}}],"schema_version":"1.7.5"}