[Buildroot] [PATCH 2025.02.x] package/sqlite: backport patch for CVE-2026-1182{2, 4}

Thomas Perale via buildroot <[email protected]>
Newsgroups net.busybox.buildroot
Message-ID <[email protected]>
- CVE-2026-11822:
    SQLite before 3.53.2 contains memory corruption vulnerabilities in the
    FTS5 full-text search extension that allow attackers to cause process
    crashes, memory exhaustion, or arbitrary code execution by supplying a
    crafted database with malformed FTS5 page data. Attackers can trigger
    an out-of-bounds read in fts5LeafSeek() via an attacker-controlled
    loop bound and a heap buffer overflow write in fts5ChunkIterate()
    through a crafted continuation page causing an integer underflow,
    exploitable when an FTS5 MATCH query is executed against the malicious
    database.

- CVE-2026-11824:
    SQLite before 3.53.2 contains a heap-based buffer overflow
    vulnerability in the FTS5 full-text search extension that allows
    attackers to cause a crash or execute arbitrary code by supplying a
    crafted database with malicious continuation page metadata specifying
    a szLeaf value smaller than 4. Attackers can trigger an integer
    underflow in fts5ChunkIterate() causing an inflated remaining byte
    count during FTS5 MATCH query processing, leading to a heap buffer
    overflow of attacker-controlled data in applications compiled with
    SQLITE_ENABLE_FTS5.

For more information, see:
 - https://www.cve.org/CVERecord?id=CVE-2026-11822
 - https://www.cve.org/CVERecord?id=CVE-2026-11824
 - https://sqlite.org/src/info/061febcf41ca
 - https://github.com/sqlite/sqlite/commit/e0b995b2a62b78979eb65bb8dadfa912eaa8e62f

Signed-off-by: Thomas Perale <[email protected]>
---
 package/sqlite/0003-CVE-2026-11822.patch | 29 ++++++++++++++++++++++++
 package/sqlite/sqlite.mk                 |  3 +++
 2 files changed, 32 insertions(+)
 create mode 100644 package/sqlite/0003-CVE-2026-11822.patch

diff --git a/package/sqlite/0003-CVE-2026-11822.patch b/package/sqlite/0003-CVE-2026-11822.patch
new file mode 100644
index 0000000000..c7386c0a9b
--- /dev/null
+++ b/package/sqlite/0003-CVE-2026-11822.patch
@@ -0,0 +1,29 @@
+From e0b995b2a62b78979eb65bb8dadfa912eaa8e62f Mon Sep 17 00:00:00 2001
+From: drh <>
+Date: Mon, 11 May 2026 12:00:19 +0000
+Subject: [PATCH] Fix potential buffer overwrite that could occur in fts5 when
+ processing corrupt records.
+
+CVE: CVE-2026-11822
+CVE: CVE-2026-11824
+Upstream: https://sqlite.org/src/info/061febcf41ca
+Upstream: https://github.com/sqlite/sqlite/commit/e0b995b2a62b78979eb65bb8dadfa912eaa8e62f
+[thomas: backport and remove tests]
+Signed-off-by: Thomas Perale <[email protected]>
+---
+ ext/fts5/fts5_index.c           |  2 +-
+ 1 files changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/ext/fts5/fts5_index.c b/ext/fts5/fts5_index.c
+index 164d613881..29be766042 100644
+--- a/sqlite3.c
++++ b/sqlite3.c
+@@ -245146,7 +245146,7 @@ static void fts5DataRelease(Fts5Data *pData){
+ static Fts5Data *fts5LeafRead(Fts5Index *p, i64 iRowid){
+   Fts5Data *pRet = fts5DataRead(p, iRowid);
+   if( pRet ){
+-    if( pRet->nn<4 || pRet->szLeaf>pRet->nn ){
++    if( pRet->szLeaf<4 || pRet->szLeaf>pRet->nn ){
+       p->rc = FTS5_CORRUPT;
+       fts5DataRelease(pRet);
+       pRet = 0;
diff --git a/package/sqlite/sqlite.mk b/package/sqlite/sqlite.mk
index 1335d0dbb2..9b0a396c7b 100644
--- a/package/sqlite/sqlite.mk
+++ b/package/sqlite/sqlite.mk
@@ -16,6 +16,9 @@ SQLITE_INSTALL_STAGING = YES
 # 0002-CVE-2025-70873.patch
 SQLITE_IGNORE_CVES += CVE-2025-70873
 
+# 0003-CVE-2026-11822.patch
+SQLITE_IGNORE_CVES += CVE-2026-11822 CVE-2026-11824
+
 ifeq ($(BR2_PACKAGE_SQLITE_STAT4),y)
 SQLITE_CFLAGS += -DSQLITE_ENABLE_STAT4
 endif
-- 
2.55.0

_______________________________________________
buildroot mailing list
[email protected]
https://lists.buildroot.org/mailman/listinfo/buildroot
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.