CVE-2026-39113
Publication date 25 August 2026
Last updated 17 September 2026
Ubuntu priority
Cvss 3 Severity Score
Description
Buffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil check-in 8bdc0d485e3ad0c7a1e818da66f106951d496b05cbe61d12c2c448f2f24b6d5d (Git mirror 169f68ed88b34cb68f720191c64c058f2ccec508, 2026-03-11) and later snapshots/builds allows an attacker to cause a denial of service via the ext/misc/sqlar.c, sqlarUncompressFunc(), sqlar_uncompress(), sqlite3_value_int64(), sqlite3_malloc(int), uncompress() components
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| sqlite | 26.04 LTS resolute | Not in release |
| 24.04 LTS noble | Not in release | |
| 22.04 LTS jammy |
Needs evaluation
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
|
| 16.04 LTS xenial |
Needs evaluation
|
|
| 14.04 LTS trusty |
Needs evaluation
|
|
| sqlite3 | 26.04 LTS resolute |
Fixed 3.46.1-9ubuntu0.3
|
| 24.04 LTS noble |
Fixed 3.45.1-1ubuntu2.8
|
|
| 22.04 LTS jammy |
Fixed 3.37.2-2ubuntu0.8
|
|
| 20.04 LTS focal |
Fixed 3.31.1-4ubuntu0.7+esm2
|
|
| 18.04 LTS bionic |
Fixed 3.22.0-1ubuntu0.7+esm3
|
|
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty |
Not affected
|
Get expanded security coverage with Ubuntu Pro
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.
Get Ubuntu Pro 30-day free trialNotes
leosilva
sqlite3: trusty and xenial are not-affected (ext/misc/sqlar.c does not exist in versions 3.8.2 and 3.11.0 respectively)
Severity score breakdown
CVSS version: CVSS v3.0
Base score
4.0 · Medium
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
References
Related Ubuntu Security Notices (USN)
- USN-8775-1
- SQLite vulnerability
- 16 September 2026