openSUSE has issued an advisory on April 15: https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/DUNGXGTRJGRYS2XF6QS2CZPSWAF5HHVJ/ Cauldron already has version 3.49.1 and Mageia 9 is only affected by CVE-2025-29088.
Upstream fix: https://github.com/sqlite/sqlite/commit/56d2fd008b108109f489339f5fd55212bb50afd4
Source RPM: (none) => sqlite3-3.40.1-1.1.mga9.src.rpmStatus comment: (none) => Patch available from upstreamCVE: (none) => CVE-2025-29088
Thanks for the patch ref. Unsure where to push this, so assigning it globally.
Assignee: bugsquad => pkg-bugs
Suggested advisory: ======================== The updated packages fix a security vulnerability: In SQLite 3.49.0 before 3.49.1, certain argument values to sqlite3_db_config (in the C-language API) can cause a denial of service (application crash). An sz*nBig multiplication is not cast to a 64-bit integer, and consequently some memory allocations may be incorrect. (CVE-2025-29088) References: https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/DUNGXGTRJGRYS2XF6QS2CZPSWAF5HHVJ/ ======================== Updated packages in core/updates_testing: ======================== lemon-3.40.1-1.2.mga9 lib(64)sqlite3_0-3.40.1-1.2.mga9 lib(64)sqlite3-devel-3.40.1-1.2.mga9 lib(64)sqlite3-static-devel-3.40.1-1.2.mga9 sqlite3-tcl-3.40.1-1.2.mga9 sqlite3-tools-3.40.1-1.2.mga9 from SRPM: sqlite3-3.40.1-1.2.mga9.src.rpm
Status: NEW => ASSIGNEDAssignee: pkg-bugs => qa-bugsStatus comment: Patch available from upstream => (none)
Keywords: (none) => advisory
MGA9-64 Plasma Wayland on Compaq H000SB. No installation issues. Ref bug 30660 for testing: With sqlitesudio created a new database and create a new table in it with a PK, not null string, other string without rules and a timestamp column. Populated a few rows, all worked OK. OK, except for one thing I didn't see on previous updates - overlooked??? The timestamp column does not show its value unless I close sqlitesudio and reopen it. But this seems to be a quack in sqlitesudio, since the insert command on sqlite3-CLI shows the timestamp immediately in a select command. So good to go.
Whiteboard: (none) => MGA9-64-OKCC: (none) => herman.viaene
Validating.
Keywords: (none) => validated_updateCC: (none) => andrewsfarm, sysadmin-bugs
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2025-0167.html
Resolution: (none) => FIXEDStatus: ASSIGNED => RESOLVED