---
id: CVE-2025-6965
title: >-
  There exists a vulnerability in SQLite versions before 3.50.2 where the number
  of aggregate terms could exceed the number of columns available
summary: >-
  There exists a vulnerability in SQLite versions before 3.50.2 where the number
  of aggregate terms could exceed the number of columns available. This could
  lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or
  above.
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L'
cwe:
  - CWE-197
vendor: sqlite
product: sqlite
affected:
  - sqlite < 3.50.2
  - ipados < 26.0.0
  - iphone_os < 26.0.0
  - macos < 26.0.0
  - tvos < 26.0.0
  - visionos < 26.0.0
  - watchos < 26.0.0
  - ruggedcom_crossbow < 5.8
  - sidis_prime < 4.0.800
patched:
  - sqlite 3.50.2
  - ipados 26.0.0
  - iphone_os 26.0.0
  - macos 26.0.0
  - tvos 26.0.0
  - visionos 26.0.0
  - watchos 26.0.0
  - ruggedcom_crossbow 5.8
  - sidis_prime 4.0.800
published: '2025-07-15'
updated: '2026-06-26'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-6965'
references:
  - url: >-
      https://www.sqlite.org/src/info/5508b56fd24016c13981ec280ecdd833007c9d8dd595edb295b984c2b487b5c8
    label: cve-coordination@google.com
  - url: 'http://seclists.org/fulldisclosure/2025/Sep/49'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2025/Sep/53'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2025/Sep/56'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2025/Sep/57'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2025/Sep/58'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2025/09/06/1'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-225816.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-485750.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-6965.json
  - url: 'https://access.redhat.com/security/cve/CVE-2025-6965'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2380149'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-6965'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-6965'
  - url: 'https://www.oracle.com/security-alerts/cpujan2026.html#AppendixMSQL'
  - url: 'https://access.redhat.com/errata/RHSA-2025:12349'
  - url: 'https://access.redhat.com/errata/RHSA-2025:19894'
  - url: 'https://access.redhat.com/errata/RHSA-2026:0934'
  - url: 'https://access.redhat.com/errata/RHSA-2025:18240'
  - url: 'https://access.redhat.com/errata/RHSA-2025:19041'
  - url: 'https://access.redhat.com/errata/RHSA-2026:62549'
  - url: 'https://access.redhat.com/errata/RHSA-2025:18218'
  - url: 'https://access.redhat.com/errata/RHSA-2025:19046'
  - url: 'https://access.redhat.com/errata/RHSA-2025:18217'
  - url: 'https://access.redhat.com/errata/RHSA-2025:15397'
  - url: 'https://access.redhat.com/errata/RHSA-2026:6481'
  - url: 'https://access.redhat.com/errata/RHSA-2025:15828'
  - url: 'https://access.redhat.com/errata/RHSA-2025:15827'
  - url: 'https://access.redhat.com/errata/RHSA-2025:11933'
  - url: 'https://access.redhat.com/errata/RHSA-2025:12010'
  - url: 'https://access.redhat.com/errata/RHSA-2025:11803'
  - url: 'https://access.redhat.com/errata/RHSA-2025:12901'
  - url: 'https://access.redhat.com/errata/RHSA-2026:0078'
  - url: 'https://access.redhat.com/errata/RHSA-2025:12905'
  - url: 'https://access.redhat.com/errata/RHSA-2026:0077'
  - url: 'https://access.redhat.com/errata/RHSA-2025:12904'
  - url: 'https://access.redhat.com/errata/RHSA-2026:0076'
  - url: 'https://access.redhat.com/errata/RHSA-2025:12521'
tags:
  - nvd
  - exploit-available
  - csaf
  - vex
  - red-hat
epss: 0.72547
epssPercentile: 0.99415
exploitAvailable: true
ingestedAt: '2026-06-26T16:43:13.607Z'
exploits:
  exploitdb: true
  checkedAt: '2026-09-23T07:13:38.419Z'
---

## Overview

There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.

## Affected

- `sqlite < 3.50.2`
- `ipados < 26.0.0`
- `iphone_os < 26.0.0`
- `macos < 26.0.0`
- `tvos < 26.0.0`
- `visionos < 26.0.0`
- `watchos < 26.0.0`
- `ruggedcom_crossbow < 5.8`
- `sidis_prime < 4.0.800`

## Remediation

Upgrade past the affected range:

- `sqlite 3.50.2`
- `ipados 26.0.0`
- `iphone_os 26.0.0`
- `macos 26.0.0`
- `tvos 26.0.0`
- `visionos 26.0.0`
- `watchos 26.0.0`
- `ruggedcom_crossbow 5.8`
- `sidis_prime 4.0.800`

## Vendor advisories

- **RHSA-2025:12349** · Red Hat · fixed in: Red Hat Enterprise Linux Server (v. 7 ELS), Red Hat Enterprise Linux Server Optional (v. 7 ELS) · released 2025-07-31 · [advisory](https://access.redhat.com/errata/RHSA-2025:12349)
- **RHSA-2025:19894** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.12 · released 2025-11-13 · [advisory](https://access.redhat.com/errata/RHSA-2025:19894)
- **RHSA-2026:0934** · Red Hat · fixed in: 8Base-Openshift-Serverless-1.36 · released 2026-01-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:0934)
- **RHSA-2025:18240** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.13 · released 2025-10-23 · [advisory](https://access.redhat.com/errata/RHSA-2025:18240)
- **RHSA-2025:19041** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.14 · released 2025-10-30 · [advisory](https://access.redhat.com/errata/RHSA-2025:19041)
- **RHSA-2026:62549** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.16 · released 2026-09-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:62549)
- **RHSA-2025:18218** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.17 · released 2025-10-22 · [advisory](https://access.redhat.com/errata/RHSA-2025:18218)
- **RHSA-2025:19046** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.18 · released 2025-10-29 · [advisory](https://access.redhat.com/errata/RHSA-2025:19046)
- **RHSA-2025:18217** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.19 · released 2025-10-22 · [advisory](https://access.redhat.com/errata/RHSA-2025:18217)
- **RHSA-2025:15397** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.20 · released 2025-10-21 · [advisory](https://access.redhat.com/errata/RHSA-2025:15397)
- **RHSA-2026:6481** · Red Hat · fixed in: Red Hat Service Interconnect 1 · released 2026-04-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:6481)
- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat OpenShift Container Platform 4 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-6965.json)
