diff --git a/sqlite-cve-2026-11824.patch b/sqlite-cve-2026-11824.patch new file mode 100644 index 0000000..ed9c4bd --- /dev/null +++ b/sqlite-cve-2026-11824.patch @@ -0,0 +1,104 @@ +From 65479ef73bfae4164083823ff591985e181119bc Mon Sep 17 00:00:00 2001 +From: dan +Date: Mon, 11 May 2026 11:12:06 +0000 +Subject: [PATCH] Fix potential buffer overwrite that could occur in fts5 when + processing corrupt records. + +FossilOrigin-Name: 4a5ad516ea93926c0d5206b4d72c3675905d2bf666b27a649256b93eb95c671b +--- + ext/fts5/fts5_index.c | 2 +- + ext/fts5/test/fts5corruptA.test | 72 +++++++++++++++++++++++++++++++++ + 2 files changed, 73 insertions(+), 1 deletion(-) + create mode 100644 ext/fts5/test/fts5corruptA.test + +diff --git a/ext/fts5/fts5_index.c b/ext/fts5/fts5_index.c +index 333fefa2d..c6ca83afb 100644 +--- a/ext/fts5/fts5_index.c ++++ b/ext/fts5/fts5_index.c +@@ -873,7 +873,7 @@ static void fts5DataRelease(Fts5Data *pData){ + static Fts5Data *fts5LeafRead(Fts5Index *p, i64 iRowid){ + Fts5Data *pRet = fts5DataRead(p, iRowid); + if( pRet ){ +- if( pRet->nn<4 || pRet->szLeaf>pRet->nn ){ ++ if( pRet->szLeaf<4 || pRet->szLeaf>pRet->nn ){ + p->rc = FTS5_CORRUPT; + fts5DataRelease(pRet); + pRet = 0; +diff --git a/ext/fts5/test/fts5corruptA.test b/ext/fts5/test/fts5corruptA.test +new file mode 100644 +index 000000000..838cded57 +--- /dev/null ++++ b/ext/fts5/test/fts5corruptA.test +@@ -0,0 +1,72 @@ ++# 2026 May 11 ++# ++# The author disclaims copyright to this source code. In place of ++# a legal notice, here is a blessing: ++# ++# May you do good and not evil. ++# May you find forgiveness for yourself and forgive others. ++# May you share freely, never taking more than you give. ++# ++#*********************************************************************** ++# ++ ++source [file join [file dirname [info script]] fts5_common.tcl] ++set testprefix fts5corruptA ++ ++# If SQLITE_ENABLE_FTS5 is not defined, omit this file. ++ifcapable !fts5 { ++ finish_test ++ return ++} ++sqlite3_fts5_may_be_corrupt 1 ++ ++do_execsql_test 1.0 { ++ CREATE VIRTUAL TABLE t USING fts5(x, detail='full'); ++ INSERT INTO t(t, rank) VALUES('pgsz', 32); ++} ++ ++set big [string repeat "a " 200] ++do_execsql_test 1.1 { ++ INSERT INTO t(rowid, x) VALUES(1, $big) ++} ++ ++do_test 1.2 { ++ db eval { ++ SELECT min(rowid) AS base_rowid, count(*) AS page_count FROM t_data ++ WHERE rowid>1000 ++ } {} ++} {} ++ ++do_test 1.3 { ++ for {set ii 0} {$ii < 5} {incr ii} { ++ db eval { ++ INSERT INTO t_data(rowid, block) ++ VALUES( $base_rowid + $page_count + $ii, zeroblob(4) ); ++ } ++ } ++ db eval { ++ INSERT INTO t_data(rowid, block) ++ VALUES( $base_rowid + $page_count + 5, ++ unhex('00000080' || 'CCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC') ); ++ } ++ set {} {} ++} {} ++ ++db close ++ ++do_test 1.4 { ++ set hex [hexio_read test.db 0 [file size test.db]] ++ ++ set off [string first "023061018310" $hex] ++ set hex [string replace $hex $off [expr $off+11] 023061018370] ++ hexio_write test.db 0 $hex ++} {6144} ++ ++sqlite3 db test.db ++ ++do_catchsql_test 1.5 { ++ SELECT rowid FROM t WHERE t MATCH 'a' ++} {1 {fts5: corruption found reading blob 137438953481 from table "t"}} ++ ++sqlite3_fts5_may_be_corrupt 0 ++finish_test diff --git a/sqlite.spec b/sqlite.spec index 853d6d2..96c9eb1 100644 --- a/sqlite.spec +++ b/sqlite.spec @@ -12,7 +12,7 @@ Summary: Library that implements an embeddable SQL database engine Name: sqlite Version: %{rpmver} -Release: 5%{?dist} +Release: 5%{?dist}.1 License: blessing URL: http://www.sqlite.org/ @@ -23,6 +23,7 @@ Source2: http://www.sqlite.org/%{year}/sqlite-autoconf-%{realver}.tar.gz Patch1: sqlite-3.6.23-lemon-system-template.patch Patch2: sqlite-cve-2025-3277.patch Patch3: sqlite-cve-2025-6965.patch +Patch4: sqlite-cve-2026-11824.patch BuildRequires: make BuildRequires: gcc @@ -128,6 +129,7 @@ This package contains the analysis program for %{name}. %patch -P 1 -p1 %patch -P 2 -p1 %patch -P 3 -p1 +%patch -P 4 -p1 # The atof test is failing on the i686 architecture, when binary configured with # --enable-rtree option. Failing part is text->real conversion and @@ -264,6 +266,10 @@ make test %endif %changelog +* Wed Jul 29 2026 RHEL Packaging Agent - 3.46.1-5.1 +- Fix CVE-2026-11824 +- Resolves: RHEL-218275 + * Wed Jul 16 2025 Ales Nezbeda - 3.46.1-5 - Fix CVE-2025-6965 - Resolves: RHEL-103827