{"id":"SUSE-SU-2026:22166-1","summary":"Security update for sqlite3","details":"This update for sqlite3 fixes the following issues\n\nUpdate to 3.53.2:\n\n- CVE-2026-11822: memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause\n  process crashes, memory exhaustion, or arbitrary code execution (bsc#1268012).\n- CVE-2026-11824: heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers\n  to cause a crash or execute arbitrary code (bsc#1268013).\n\nChanges:\n\n * Add the Query Result Formatter (QRF) library for formatting the\n results of SQL queries for human readability on a fixed-pitch\n font screen.\n * Enhance ALTER TABLE to permit adding and removing NOT NULL and\n CHECK constraints.\n * The REINDEX EXPRESSIONS statement rebuilds expression indexes.\n * The body of TEMP triggers may now modify and/or query tables\n in the main schema.\n * Enhance VACUUM INTO so that if a URI filename is used as the\n target and that filename has a reserve=N query parameter with\n N between 0 and 255, then the reserve amount for the generated\n database copy is set to N.\n * New SQL functions json_array_insert() and jsonb_array_insert().\n * Renovations to the CLI.\n * New C-language interfaces: sqlite3_str_truncate(),\n sqlite3_str_free(), sqlite3_carray_bind_v2().\n * Add the SQLITE_PREPARE_FROM_DDL option to sqlite3_prepare_v3().\n * Added the SQLITE_UTF8_ZT constant which can be used as the\n encoding parameter to sqlite3_result_text64() or\n sqlite3_bind_text64() to indicate that the value is UTF-8\n encoded and zero terminated.\n * The SQLITE_LIMIT_PARSER_DEPTH option is added to\n sqlite3_limit().\n * The SQLITE_DBCONFIG_FP_DIGITS option is added to\n sqlite3_db_config().\n * Query planner improvements.\n * Add new interfaces to the session extension that enable an\n application to add changes one at a time to the\n sqlite3_changegroup object.\n * Improvements to floating-point \u003c-\u003e text conversions.\n * Added the self-healing index feature to deal with the stale\n expression index problem.\n * Add the \"-p|--port\" option to sqlite3_rsync.\n * Add the \"opfs-wl\" VFS, functionally identical to the \"opfs\" VFS\n but using Web Locks for locking, which can promise fairer lock\n sharing than the \"opfs\" bespoke protocol can. \"opfs-wl\"\n requires Atomics.waitAsync(), so requires newer browsers than\n \"opfs\" does.\n * Fixes for problems in 3.53.0 and 3.53.1 reported by users.\n * See the check-in timeline for details:\n https://sqlite.org/src/timeline?from=version-3.53.0&to=version-3.53.2\n\n * https://sqlite.org/releaselog/3_53_0.html\n","modified":"2026-06-24T18:24:21.596553786Z","published":"2026-06-18T20:59:46Z","related":["CVE-2026-11822","CVE-2026-11824"],"upstream":["CVE-2026-11822","CVE-2026-11824"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202622166-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268012"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268013"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11822"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11824"}],"affected":[{"package":{"name":"sqlite3","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/sqlite3&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.53.2-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"sqlite3-devel":"3.53.2-160000.1.1","sqlite3-doc":"3.53.2-160000.1.1","sqlite3-tcl":"3.53.2-160000.1.1","libsqlite3-0":"3.53.2-160000.1.1","libsqlite3-0-x86-64-v3":"3.53.2-160000.1.1","sqlite3":"3.53.2-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22166-1.json"}},{"package":{"name":"sqlite3","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/sqlite3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.53.2-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"sqlite3-tcl":"3.53.2-160000.1.1","libsqlite3-0":"3.53.2-160000.1.1","libsqlite3-0-x86-64-v3":"3.53.2-160000.1.1","sqlite3":"3.53.2-160000.1.1","sqlite3-devel":"3.53.2-160000.1.1","sqlite3-doc":"3.53.2-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22166-1.json"}}],"schema_version":"1.7.5"}