Fix CVE-2026-11824: fts5 buffer overwrite on corrupt records

Backport upstream fix for CVE-2026-11824 to sqlite 3.46.1.
The fix corrects a bounds check in fts5LeafRead() (changing
pRet->nn<4 to pRet->szLeaf<4) to prevent a potential buffer
overwrite when processing corrupt fts5 records.

CVE: CVE-2026-11824
Upstream patches:
 - https://github.com/sqlite/sqlite/commit/79db323ce149.patch
Resolves: RHEL-218275

This commit was backported by Ymir, a Red Hat Enterprise Linux software maintenance AI agent.

Assisted-by: Ymir
This commit is contained in:
RHEL Packaging Agent 2026-07-29 10:48:18 +00:00 committed by Petr Khartskhaev
parent e9896988a3
commit a6aa59f487
2 changed files with 111 additions and 1 deletions

104
sqlite-cve-2026-11824.patch Normal file
View File

@ -0,0 +1,104 @@
From 65479ef73bfae4164083823ff591985e181119bc Mon Sep 17 00:00:00 2001
From: dan <Dan Kennedy>
Date: Mon, 11 May 2026 11:12:06 +0000
Subject: [PATCH] Fix potential buffer overwrite that could occur in fts5 when
processing corrupt records.
FossilOrigin-Name: 4a5ad516ea93926c0d5206b4d72c3675905d2bf666b27a649256b93eb95c671b
---
ext/fts5/fts5_index.c | 2 +-
ext/fts5/test/fts5corruptA.test | 72 +++++++++++++++++++++++++++++++++
2 files changed, 73 insertions(+), 1 deletion(-)
create mode 100644 ext/fts5/test/fts5corruptA.test
diff --git a/ext/fts5/fts5_index.c b/ext/fts5/fts5_index.c
index 333fefa2d..c6ca83afb 100644
--- a/ext/fts5/fts5_index.c
+++ b/ext/fts5/fts5_index.c
@@ -873,7 +873,7 @@ static void fts5DataRelease(Fts5Data *pData){
static Fts5Data *fts5LeafRead(Fts5Index *p, i64 iRowid){
Fts5Data *pRet = fts5DataRead(p, iRowid);
if( pRet ){
- if( pRet->nn<4 || pRet->szLeaf>pRet->nn ){
+ if( pRet->szLeaf<4 || pRet->szLeaf>pRet->nn ){
p->rc = FTS5_CORRUPT;
fts5DataRelease(pRet);
pRet = 0;
diff --git a/ext/fts5/test/fts5corruptA.test b/ext/fts5/test/fts5corruptA.test
new file mode 100644
index 000000000..838cded57
--- /dev/null
+++ b/ext/fts5/test/fts5corruptA.test
@@ -0,0 +1,72 @@
+# 2026 May 11
+#
+# The author disclaims copyright to this source code. In place of
+# a legal notice, here is a blessing:
+#
+# May you do good and not evil.
+# May you find forgiveness for yourself and forgive others.
+# May you share freely, never taking more than you give.
+#
+#***********************************************************************
+#
+
+source [file join [file dirname [info script]] fts5_common.tcl]
+set testprefix fts5corruptA
+
+# If SQLITE_ENABLE_FTS5 is not defined, omit this file.
+ifcapable !fts5 {
+ finish_test
+ return
+}
+sqlite3_fts5_may_be_corrupt 1
+
+do_execsql_test 1.0 {
+ CREATE VIRTUAL TABLE t USING fts5(x, detail='full');
+ INSERT INTO t(t, rank) VALUES('pgsz', 32);
+}
+
+set big [string repeat "a " 200]
+do_execsql_test 1.1 {
+ INSERT INTO t(rowid, x) VALUES(1, $big)
+}
+
+do_test 1.2 {
+ db eval {
+ SELECT min(rowid) AS base_rowid, count(*) AS page_count FROM t_data
+ WHERE rowid>1000
+ } {}
+} {}
+
+do_test 1.3 {
+ for {set ii 0} {$ii < 5} {incr ii} {
+ db eval {
+ INSERT INTO t_data(rowid, block)
+ VALUES( $base_rowid + $page_count + $ii, zeroblob(4) );
+ }
+ }
+ db eval {
+ INSERT INTO t_data(rowid, block)
+ VALUES( $base_rowid + $page_count + 5,
+ unhex('00000080' || 'CCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC') );
+ }
+ set {} {}
+} {}
+
+db close
+
+do_test 1.4 {
+ set hex [hexio_read test.db 0 [file size test.db]]
+
+ set off [string first "023061018310" $hex]
+ set hex [string replace $hex $off [expr $off+11] 023061018370]
+ hexio_write test.db 0 $hex
+} {6144}
+
+sqlite3 db test.db
+
+do_catchsql_test 1.5 {
+ SELECT rowid FROM t WHERE t MATCH 'a'
+} {1 {fts5: corruption found reading blob 137438953481 from table "t"}}
+
+sqlite3_fts5_may_be_corrupt 0
+finish_test

View File

@ -12,7 +12,7 @@
Summary: Library that implements an embeddable SQL database engine
Name: sqlite
Version: %{rpmver}
Release: 5%{?dist}
Release: 5%{?dist}.1
License: blessing
URL: http://www.sqlite.org/
@ -23,6 +23,7 @@ Source2: http://www.sqlite.org/%{year}/sqlite-autoconf-%{realver}.tar.gz
Patch1: sqlite-3.6.23-lemon-system-template.patch
Patch2: sqlite-cve-2025-3277.patch
Patch3: sqlite-cve-2025-6965.patch
Patch4: sqlite-cve-2026-11824.patch
BuildRequires: make
BuildRequires: gcc
@ -128,6 +129,7 @@ This package contains the analysis program for %{name}.
%patch -P 1 -p1
%patch -P 2 -p1
%patch -P 3 -p1
%patch -P 4 -p1
# The atof test is failing on the i686 architecture, when binary configured with
# --enable-rtree option. Failing part is text->real conversion and
@ -264,6 +266,10 @@ make test
%endif
%changelog
* Wed Jul 29 2026 RHEL Packaging Agent <redhat-ymir-agent@redhat.com> - 3.46.1-5.1
- Fix CVE-2026-11824
- Resolves: RHEL-218275
* Wed Jul 16 2025 Ales Nezbeda <anezbeda@redhat.com> - 3.46.1-5
- Fix CVE-2025-6965
- Resolves: RHEL-103827