{"id":"CVE-2025-29088","details":"In SQLite 3.49.0 before 3.49.1, certain argument values to sqlite3_db_config (in the C-language API) can cause a denial of service (application crash). An sz*nBig multiplication is not cast to a 64-bit integer, and consequently some memory allocations may be incorrect.","aliases":["BIT-sqlite-2025-29088"],"modified":"2026-04-16T04:36:17.012540440Z","published":"2025-04-10T14:15:27.163Z","related":["SUSE-SU-2025:01455-1","SUSE-SU-2025:01456-1","SUSE-SU-2025:01456-2","SUSE-SU-2025:1455-1","SUSE-SU-2025:1456-1","SUSE-SU-2025:20323-1","SUSE-SU-2025:20395-1","openSUSE-SU-2025:14991-1"],"references":[{"type":"ADVISORY","url":"https://sqlite.org/forum/forumpost/48f365daec"},{"type":"ADVISORY","url":"https://sqlite.org/releaselog/3_49_1.html"},{"type":"ADVISORY","url":"https://www.sqlite.org/cves.html"},{"type":"ADVISORY","url":"https://gist.github.com/ylwango613/d3883fb9f6ba8a78086356779ce88248"},{"type":"FIX","url":"https://github.com/sqlite/sqlite/commit/56d2fd008b108109f489339f5fd55212bb50afd4"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/sqlite/sqlite","events":[{"introduced":"0"},{"last_affected":"659bafd05dee789298074283ce857e27e65ef675"},{"fixed":"56d2fd008b108109f489339f5fd55212bb50afd4"}],"database_specific":{"versions":[{"introduced":"0"},{"last_affected":"3.49.0"}]}}],"versions":["major-relase","relase","same-as-3.35.3","version-1.0","version-1.0.1","version-1.0.10","version-1.0.12","version-1.0.13","version-1.0.14","version-1.0.15","version-1.0.16","version-1.0.17","version-1.0.18","version-1.0.19","version-1.0.20","version-1.0.21","version-1.0.22","version-1.0.23","version-1.0.24","version-1.0.25","version-1.0.26","version-1.0.27","version-1.0.28","version-1.0.29","version-1.0.3","version-1.0.30","version-1.0.31","version-1.0.32","version-1.0.4","version-1.0.5","version-1.0.8","version-1.0.9","version-2.0.0","version-2.0.1","version-2.0.2","version-2.0.3","version-2.0.4","version-2.0.5","version-2.0.6","version-2.0.7","version-2.0.8","version-2.1.0","version-2.1.1","version-2.1.2","version-2.1.3","version-2.1.4","version-2.1.5","version-2.1.6","version-2.1.7","version-2.2.0","version-2.2.1","version-2.2.2","version-2.2.3","version-2.2.4","version-2.2.5","version-2.3.0","version-2.3.1","version-2.3.2","version-2.3.3","version-2.4.0","version-2.4.1","version-2.4.10","version-2.4.11","version-2.4.12","version-2.4.2","version-2.4.3","version-2.4.4","version-2.4.5","version-2.4.6","version-2.4.7","version-2.4.8","version-2.4.9","version-2.5.0","version-2.5.1","version-2.5.2","version-2.5.3","version-2.5.4","version-2.5.5","version-2.5.6","version-2.6.0","version-2.6.1","version-2.6.2","version-2.6.3","version-2.7.0","version-2.7.1","version-2.7.2","version-2.7.3","version-2.7.4","version-2.7.5","version-2.7.6","version-2.8.0","version-2.8.1","version-2.8.10","version-2.8.11","version-2.8.12","version-2.8.13","version-2.8.2","version-2.8.3","version-2.8.4","version-2.8.5","version-2.8.6","version-2.8.7","version-2.8.8","version-2.8.9","version-3.0.0","version-3.0.1","version-3.0.2","version-3.0.3","version-3.0.4","version-3.0.5","version-3.0.6","version-3.0.7","version-3.0.8","version-3.1.0","version-3.1.1","version-3.1.2","version-3.1.3","version-3.1.3.1","version-3.1.4","version-3.1.5","version-3.1.6","version-3.10.0","version-3.11.0","version-3.12.0","version-3.13.0","version-3.14.0","version-3.15.0","version-3.16.0","version-3.2.0","version-3.2.1","version-3.2.2","version-3.2.3","version-3.2.4","version-3.2.5","version-3.2.6","version-3.2.7","version-3.22.0","version-3.23.0","version-3.23.1","version-3.24.0","version-3.25.0","version-3.26.0","version-3.27.0","version-3.28.0","version-3.29.0","version-3.3.0","version-3.3.1","version-3.3.10","version-3.3.11","version-3.3.12","version-3.3.13","version-3.3.14","version-3.3.15","version-3.3.16","version-3.3.17","version-3.3.2","version-3.3.3","version-3.3.4","version-3.3.5","version-3.3.6","version-3.3.7","version-3.3.8","version-3.3.9","version-3.30.0","version-3.31.0","version-3.31.1","version-3.32.0","version-3.32.1","version-3.33.0","version-3.34.0","version-3.35.0","version-3.35.1","version-3.35.2","version-3.36.0","version-3.37.0","version-3.38.0","version-3.39.0","version-3.4.0","version-3.4.1","version-3.4.2","version-3.40.0","version-3.41.0","version-3.42.0","version-3.43.0","version-3.44.0","version-3.45.0","version-3.46.0","version-3.47.0","version-3.48.0","version-3.49.0","version-3.5.0","version-3.5.1","version-3.5.2","version-3.5.3","version-3.5.4","version-3.5.5","version-3.5.6","version-3.5.7","version-3.5.8","version-3.5.9","version-3.6.0","version-3.6.1","version-3.6.10","version-3.6.11","version-3.6.12","version-3.6.13","version-3.6.14","version-3.6.15","version-3.6.16","version-3.6.17","version-3.6.18","version-3.6.19","version-3.6.2","version-3.6.20","version-3.6.21","version-3.6.22","version-3.6.23","version-3.6.3","version-3.6.4","version-3.6.5","version-3.6.6","version-3.6.7","version-3.6.8","version-3.6.9","version-3.7.0","version-3.7.1","version-3.7.10","version-3.7.11","version-3.7.12","version-3.7.12.1","version-3.7.13","version-3.7.14","version-3.7.15","version-3.7.16","version-3.7.16.1","version-3.7.17","version-3.7.2","version-3.7.3","version-3.7.4","version-3.7.5","version-3.7.6","version-3.7.6.1","version-3.7.7","version-3.7.8","version-3.7.9","version-3.8.0","version-3.8.1","version-3.8.10","version-3.8.10.1","version-3.8.11","version-3.8.11.1","version-3.8.2","version-3.8.3","version-3.8.4","version-3.8.4.1","version-3.8.5","version-3.8.6","version-3.8.7","version-3.8.8","version-3.8.9","version-3.9.0"],"database_specific":{"vanir_signatures":[{"signature_type":"Function","target":{"function":"setupLookaside","file":"src/main.c"},"source":"https://github.com/sqlite/sqlite/commit/56d2fd008b108109f489339f5fd55212bb50afd4","id":"CVE-2025-29088-69bc8e80","digest":{"function_hash":"5429052069220559463260089493636071609","length":2737},"deprecated":false,"signature_version":"v1"},{"signature_type":"Line","digest":{"threshold":0.9,"line_hashes":["39826769564372032825417142920266208978","131744436590503758423334362165627665526","156887614002996371651060072260617843233","22136163177545101843723995456546001038","159263920347785671602192097111218575962","269888135610323103955213216169360149096","100507046096844854820297547028498584049","137860169083551923182255130981399545593","169295985084664084716035143178358945038","224581361444588764553703061731657690862","254961715956719408494865708781294070951","34367095266247901411946366506791138213","85749957422984725276054991603402471436","289160059118046469697642598445374425411","264931618189465631739270240648043167270","153711847611322404467672144729869832259","88819407589660696616667168905306560324","78310239316019648382233471021170002623","309044393595509933975460334536793728981","65788192120267222678882514538643449038","195859394979415466483821601830902246210","100976245618461176497342310742969343975","157649672884947916678494037889427738783","288640495902043871289867985079375707513","321759326460408989197929602329010527698","137397909491990842435116783858523105752","48151367006986126524073095391989941746","222700987374964209519243816746825526612"]},"source":"https://github.com/sqlite/sqlite/commit/56d2fd008b108109f489339f5fd55212bb50afd4","id":"CVE-2025-29088-feb7f724","target":{"file":"src/main.c"},"deprecated":false,"signature_version":"v1"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-29088.json","vanir_signatures_modified":"2026-04-12T15:44:29Z"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}