A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows an attacker who can supply a malformed changeset blob to cause a denial of service. The issue occurs when sqlite3changeset_apply_v3() applies a corrupt changeset and reaches sqlite3_value_type() with a NULL sqlite3_value pointer.

Project Subscriptions

Vendors Products
Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8565-1 SQLite vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 31 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title SQLite Session Extension NULL Pointer Dereference Enables Denial of Service with Malformed Changesets

Sun, 26 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title SQLite Session Extension NULL Pointer Dereference Enables Denial of Service with Malformed Changesets

Thu, 23 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Null Pointer Dereference in SQLite Session Extension Causes DoS

Tue, 21 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Null Pointer Dereference in SQLite Session Extension Causes DoS

Fri, 17 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title SQLite NULL Pointer Dereference in Session Extension Leading to Denial of Service

Wed, 15 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title SQLite NULL Pointer Dereference in Session Extension Leading to Denial of Service

Tue, 14 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title SQLite Session Extension NULL Pointer Dereference Causing Denial of Service

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title SQLite Session Extension NULL Pointer Dereference Causing Denial of Service

Sat, 11 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Null Pointer Dereference in SQLite Session Extension Causing Denial of Service

Fri, 10 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Null Pointer Dereference in SQLite Session Extension Causing Denial of Service

Fri, 10 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title SQLite Session Extension NULL Pointer Dereference Leads to Denial of Service

Thu, 09 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title SQLite Session Extension NULL Pointer Dereference Leads to Denial of Service

Wed, 08 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Sqlite
Sqlite sqlite
Vendors & Products Sqlite
Sqlite sqlite

Wed, 08 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Description A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows an attacker who can supply a malformed changeset blob to cause a denial of service. The issue occurs when sqlite3changeset_apply_v3() applies a corrupt changeset and reaches sqlite3_value_type() with a NULL sqlite3_value pointer.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-08T20:11:45.210Z

Reserved: 2026-06-07T00:00:00.000Z

Link: CVE-2026-50812

cve-icon Vulnrichment

Updated: 2026-07-08T20:10:29.574Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T14:15:03Z

Weaknesses