CVE-2025-6965 Affecting mingw64-sqlite package, versions <0:3.26.0.0-2.el8_10


Severity

Recommended
high

Based on Oracle Linux security rating.

Threat Intelligence

Social Trends
Exploit Maturity
Proof of Concept
EPSS
72.55% (100th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-ORACLE8-MINGW64SQLITE-12088917
  • published21 Aug 2025
  • disclosed15 Jul 2025

Introduced: 15 Jul 2025

CVE-2025-6965  (opens in a new tab)

How to fix?

Upgrade Oracle:8 mingw64-sqlite to version 0:3.26.0.0-2.el8_10 or higher.
This issue was patched in ELSA-2025-14101.

NVD Description

Note: Versions mentioned in the description apply only to the upstream mingw64-sqlite package and not the mingw64-sqlite package as distributed by Oracle. See How to fix? for Oracle:8 relevant fixed versions and status.

There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.

CVSS Base Scores

version 3.1