diff --git a/SOURCES/sqlite-3.34.1-CVE-2026-11822-CVE-2026-11824.patch b/SOURCES/sqlite-3.34.1-CVE-2026-11822-CVE-2026-11824.patch new file mode 100644 index 0000000..ff0e530 --- /dev/null +++ b/SOURCES/sqlite-3.34.1-CVE-2026-11822-CVE-2026-11824.patch @@ -0,0 +1,76 @@ +Index: ext/fts5/fts5_index.c +================================================================== +--- a/ext/fts5/fts5_index.c ++++ b/ext/fts5/fts5_index.c +@@ -708,7 +708,7 @@ static void fts5DataRelease(Fts5Data *pData){ + static Fts5Data *fts5LeafRead(Fts5Index *p, i64 iRowid){ + Fts5Data *pRet = fts5DataRead(p, iRowid); + if( pRet ){ +- if( pRet->nn<4 || pRet->szLeaf>pRet->nn ){ ++ if( pRet->szLeaf<4 || pRet->szLeaf>pRet->nn ){ + p->rc = FTS5_CORRUPT; + fts5DataRelease(pRet); + pRet = 0; +ADDED ext/fts5/test/fts5corruptA.test +Index: ext/fts5/test/fts5corruptA.test +================================================================== +--- /dev/null ++++ b/ext/fts5/test/fts5corruptA.test +@@ -0,0 +1,57 @@ ++# 2026 May 11 ++# ++# The author disclaims copyright to this source code. In place of ++# a legal notice, here is a blessing: ++# ++# May you do good and not evil. ++# May you find forgiveness for yourself and forgive others. ++# May you share freely, never taking more than you give. ++# ++#*********************************************************************** ++# ++ ++source [file join [file dirname [info script]] fts5_common.tcl] ++set testprefix fts5corruptA ++ ++# If SQLITE_ENABLE_FTS5 is not defined, omit this file. ++ifcapable !fts5 { ++ finish_test ++ return ++} ++sqlite3_fts5_may_be_corrupt 1 ++ ++do_execsql_test 1.0 { ++ CREATE VIRTUAL TABLE t USING fts5(x, detail='full'); ++ INSERT INTO t(t, rank) VALUES('pgsz', 32); ++} ++ ++set big [string repeat "a " 200] ++do_execsql_test 1.1 { ++ INSERT INTO t(rowid, x) VALUES(1, $big) ++} ++ ++do_test 1.2 { ++ db eval { ++ SELECT min(rowid) AS base_rowid, count(*) AS page_count FROM t_data ++ WHERE rowid>1000 ++ } {} ++} {} ++ ++db close ++ ++do_test 1.4 { ++ set hex [hexio_read test.db 0 [file size test.db]] ++ ++ set off [string first "023061018310" $hex] ++ set hex [string replace $hex $off [expr $off+11] 023061018370] ++ hexio_write test.db 0 $hex ++} {6144} ++ ++sqlite3 db test.db ++ ++do_catchsql_test 1.5 { ++ SELECT rowid FROM t WHERE t MATCH 'a' ++} {1 {database disk image is malformed}} ++ ++sqlite3_fts5_may_be_corrupt 0 ++finish_test diff --git a/SPECS/sqlite.spec b/SPECS/sqlite.spec index ec29ad7..bda3691 100644 --- a/SPECS/sqlite.spec +++ b/SPECS/sqlite.spec @@ -12,7 +12,7 @@ Summary: Library that implements an embeddable SQL database engine Name: sqlite Version: %{rpmver} -Release: 10%{?dist} +Release: 11%{?dist} License: Public Domain URL: http://www.sqlite.org/ @@ -37,6 +37,8 @@ Patch6: sqlite-3.34.1-covscan-rhel-9.patch Patch7: sqlite-3.26.0-CVE-2022-35737.patch Patch8: sqlite-3.34.1-CVE-2023-7104.patch Patch9: sqlite-3.34.1-CVE-2025-6965.patch +# https://sqlite.org/src/info/4a5ad516ea93 +Patch10: sqlite-3.34.1-CVE-2026-11822-CVE-2026-11824.patch BuildRequires: make BuildRequires: gcc @@ -149,6 +151,7 @@ This package contains the analysis program for %{name}. %patch -P 7 -p1 %patch -P 8 -p1 %patch -P 9 -p1 +%patch -P 10 -p1 # Remove backup-file rm -f %{name}-doc-%{docver}/sqlite.css~ || : @@ -268,6 +271,14 @@ make test %endif %changelog +* Wed Jul 29 2026 RHEL Packaging Agent - 3.34.1-11 +- Fixes CVE-2026-11822 +- Resolves: RHEL-218273 + +* Wed Jul 29 2026 RHEL Packaging Agent - 3.34.1-10.1 +- Fixes CVE-2026-11824 +- Resolves: RHEL-218281 + * Tue Mar 17 2026 Petr Khartskhaev - 3.34.1-10 - Enable sqlite3_deserialize and sqlite3_serialize interfaces - Resolves: RHEL-155950