CVE-2026-11822Patch(sqlite / sqlite)

LOWCVSS 8.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch sqlite sqlite systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sqlite

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-06-17); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
sqlite

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-06-17: 1Mentions · 2026-06-18: 1Mentions · 2026-06-24: 1Patch / Workaround · 2026-06-18: 1Patch / Workaround · 2026-06-24: 1Technical Details · 2026-06-17: 1Technical Details · 2026-06-18: 1Technical Details · 2026-06-24: 106-1706-1806-24
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-06-171
Disclosure1
2026-06-181
Patch1
2026-06-241
Patch1
Full discourse3 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🚨 SUSE-SU-2026:2527-1: sqlite3 3.53.2 (IMPORTANTE). Corrige CVE-2026-11822/24 - RCE via FTS5 (CVSS 8.5). Saiba mais: -> http://tinyurl.com/3scsdeps #SUSE https://t.co/Lx4ZWSa0gk

    Post summary

    The tweet announces a SUSE update that patches CVE-2026-11822/24, an RCE in sqlite3 via FTS5, and links to further details.

    1000069
    1.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🛡️ SQLite3 no #SUSE: duas vulnerabilidades críticas no FTS5 (CVE-2026-11822 e CVE-2026-11824) foram corrigidas. Saiba mais: -> http://tinyurl.com/2wyu89a4 https://t.co/dhQRRtEjsC

    Post summary

    The post announces that two critical SQLite3 FTS5 vulnerabilities (CVE‑2026‑11822 and CVE‑2026‑11824) on SUSE have been patched, directing readers to a link for further information.

    1000055
    1.5K followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    SUSE sqlite2/sqlite3 FTS5 bugs CVE-2026-11822 and CVE-2026-11824 allow memory corruption and possible arbitrary code execution. - Affects SUSE systems shipping sqlite for software that enables the FTS5 full text extension. #Ransomware #InfoSec https://t.co/AeEXm5kBtR

    Post summary

    The tweet announces two SUSE SQLite FTS5 vulnerabilities (CVE-2026-11822 and CVE-2026-11824) that can lead to memory corruption and potential arbitrary code execution, but offers no PoC, exploit code, or patch information.

    1000092
    356 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsqlitesqlite---

Explore more