CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

NCSC-2026-0268 [1.00] [M/H] Vulnerability fixed in SQLite by SQLite Consortium

unknownpublic exploitCVE-2026-51302
SQLite Consortium has fixed a vulnerability in SQLite version 3.41. The vulnerability concerns a use-after-free in the expression evaluation logic of SQLite. An attacker can exploit this vulnerability remotely by providing specially crafted malicious SQL statements. Exploitation can lead to arbitrary code execution, leakage of sensitive information, or denial of service. The vulnerability arises from improper memory management during the evaluation of expressions. Systems using SQLite, including products from Red Hat, are affected.

CSIRTS triage

What
A use-after-free vulnerability in SQLite can lead to arbitrary code execution, information leakage, or denial of service.
Who is affected
Systems using SQLite version 3.41, including products from Red Hat.
Urgency
Remediation is urgent due to the potential for remote exploitation and high impact.
Action
Upgrade to the patched version of SQLite.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch SQLite

Get an email when a new SQLite advisory drops — max one per day, one-click unsubscribe.

Details

Source
NCSC-NL Advisories (NL · national-cert · site)
Severity
unknown
Published
2026-07-29
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0268

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-51302coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from NCSC-NL Advisories