{"id":"CVE-2025-29088","details":"In SQLite 3.49.0 before 3.49.1, certain argument values to sqlite3_db_config (in the C-language API) can cause a denial of service (application crash). An sz*nBig multiplication is not cast to a 64-bit integer, and consequently some memory allocations may be incorrect.","aliases":["BIT-sqlite-2025-29088"],"modified":"2026-08-12T03:51:20.459121256Z","published":"2025-04-10T00:00:00Z","related":["SUSE-SU-2025:01455-1","SUSE-SU-2025:01456-1","SUSE-SU-2025:01456-2","SUSE-SU-2025:1455-1","SUSE-SU-2025:1456-1","SUSE-SU-2025:20323-1","SUSE-SU-2025:20395-1","openSUSE-SU-2025:14991-1"],"database_specific":{"cwe_ids":["CWE-190"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/29xxx/CVE-2025-29088.json","cna_assigner":"mitre"},"references":[{"type":"WEB","url":"https://gist.github.com/ylwango613/d3883fb9f6ba8a78086356779ce88248"},{"type":"WEB","url":"https://sqlite.org/forum/forumpost/48f365daec"},{"type":"WEB","url":"https://sqlite.org/releaselog/3_49_1.html"},{"type":"WEB","url":"https://www.sqlite.org/cves.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/29xxx/CVE-2025-29088.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-29088"},{"type":"FIX","url":"https://github.com/sqlite/sqlite/commit/56d2fd008b108109f489339f5fd55212bb50afd4"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/sqlite/sqlite","events":[{"introduced":"659bafd05dee789298074283ce857e27e65ef675"},{"fixed":"3cd92ce875fd4e5601e535c35fef33494a6684e3"}],"database_specific":{"extracted_events":[{"introduced":"3.49.0"},{"fixed":"3.49.1"}],"source":"AFFECTED_FIELD"}}],"versions":["3.49.0","version-3.49.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-29088.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L"}]}