CVE-2025-7458 - CVE House
Back to Database
Status published Medium CVE-2025-7458

SQLite integer overflow in key info allocation may lead to information disclosure.

Vulnerability Description

An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive information from process memory via a crafted SELECT statement with a large number of expressions in the ORDER BY clause.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-7458

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • sec.r1nd0@gmail.com

Affected Vendor

Affected Software

SQLite
Vulnerable Versions:
3.39.2

Timeline

Official Publish: July 29th, 2025
Last Modified: July 29th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)