In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compound SELECT statement.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HNetapp Ontap Select Deploy Administration Utility
APPNetappall versionsOracle Communications Messaging Server
OSOracle8.1Oracle Communications Network Charging And Control
APPOracle12.0.26.0.112.0.0 – 12.0.3Oracle Enterprise Manager Ops Center
APPOracle12.4.0.0Oracle Hyperion Infrastructure Technology
APPOracle11.1.2.4Oracle MySQL
APPOracle8.0.0 – 8.0.22Oracle MySQL Workbench
APPOracle≤ 8.0.22Oracle Outside In Technology
APPOracle8.5.48.5.5Oracle Zfs Storage Appliance Kit
APPOracle8.8Siemens Sinec Infrastructure Network Services
APPSiemens< 1.0.1.1Sqlite
APPSqlite≤ 3.31.1Tenable Tenable.sc
APPTenable≤ 5.19.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Memory
CWE
References
Related vulnerabilities
CVE-2021-40438CRITICAL9.0⚠ KEVPL ✓same product
SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego
CVE-2020-15999CRITICAL9.6⚠ KEVPL ✓same product
Heap buffer overflow w FreeType w Google Chrome — aktywnie exploitowany
CVE-2026-62457CRITICAL9.8same product
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common E...
CVE-2026-62463CRITICAL9.6same product
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycl...
CVE-2026-62539CRITICAL9.8same product
Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installa...