public inbox for git-commits@fedoraproject.org
help / color / mirror / Atom feed
* [rpms/sqlite] f44: Fix CVE-2026-11822 and CVE-2026-11824
@ 2026-08-11 10:42 Petr Khartskhaev
  0 siblings, 0 replies; only message in thread
From: Petr Khartskhaev @ 2026-08-11 10:42 UTC (permalink / raw)
  To: git-commits

A new commit has been pushed.

Repo   : rpms/sqlite
Branch : f44
Commit : c5d4547ea5c96fbd33637cb8dfa99903e5fd45fb
Author : Petr Khartskhaev <pkhartsk@redhat.com>
Date   : 2026-08-10T16:16:42+02:00
Stats  : +102/-1 in 2 file(s)
URL    : https://src.fedoraproject.org/rpms/sqlite/c/c5d4547ea5c96fbd33637cb8dfa99903e5fd45fb?branch=f44

Log:
Fix CVE-2026-11822 and CVE-2026-11824

---
diff --git a/sqlite-3.51.2-CVE-2026-11822-CVE-2026-11824.patch b/sqlite-3.51.2-CVE-2026-11822-CVE-2026-11824.patch
new file mode 100644
index 0000000..e610bf0
--- /dev/null
+++ b/sqlite-3.51.2-CVE-2026-11822-CVE-2026-11824.patch
@@ -0,0 +1,96 @@
+Index: ext/fts5/fts5_index.c
+==================================================================
+--- a/ext/fts5/fts5_index.c	
++++ b/ext/fts5/fts5_index.c	
+@@ -920,11 +920,11 @@
+ }
+ 
+ static Fts5Data *fts5LeafRead(Fts5Index *p, i64 iRowid){
+   Fts5Data *pRet = fts5DataRead(p, iRowid);
+   if( pRet ){
+-    if( pRet->nn<4 || pRet->szLeaf>pRet->nn ){
++    if( pRet->szLeaf<4 || pRet->szLeaf>pRet->nn ){
+       FTS5_CORRUPT_ROWID(p, iRowid);
+       fts5DataRelease(pRet);
+       pRet = 0;
+     }
+   }
+
+ADDED   ext/fts5/test/fts5corruptA.test
+Index: ext/fts5/test/fts5corruptA.test
+==================================================================
+--- /dev/null	
++++ b/ext/fts5/test/fts5corruptA.test	
+@@ -0,0 +1,72 @@
++# 2026 May 11
++#
++# The author disclaims copyright to this source code.  In place of
++# a legal notice, here is a blessing:
++#
++#    May you do good and not evil.
++#    May you find forgiveness for yourself and forgive others.
++#    May you share freely, never taking more than you give.
++#
++#***********************************************************************
++#
++
++source [file join [file dirname [info script]] fts5_common.tcl]
++set testprefix fts5corruptA
++
++# If SQLITE_ENABLE_FTS5 is not defined, omit this file.
++ifcapable !fts5 {
++  finish_test
++  return
++}
++sqlite3_fts5_may_be_corrupt 1
++
++do_execsql_test 1.0 {
++  CREATE VIRTUAL TABLE t USING fts5(x, detail='full');
++  INSERT INTO t(t, rank) VALUES('pgsz', 32);
++}
++
++set big [string repeat "a " 200]
++do_execsql_test 1.1 {
++  INSERT INTO t(rowid, x) VALUES(1, $big)
++}
++
++do_test 1.2 {
++  db eval { 
++      SELECT min(rowid) AS base_rowid, count(*) AS page_count FROM t_data
++      WHERE rowid>1000
++  } {}
++} {}
++
++do_test 1.3 {
++  for {set ii 0} {$ii < 5} {incr ii} {
++    db eval { 
++      INSERT INTO t_data(rowid, block) 
++      VALUES( $base_rowid + $page_count + $ii, zeroblob(4) );
++    }
++  }
++  db eval { 
++    INSERT INTO t_data(rowid, block) 
++      VALUES( $base_rowid + $page_count + 5, 
++      unhex('00000080' || 'CCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC') );
++  }
++  set {} {}
++} {}
++
++db close
++
++do_test 1.4 {
++  set hex [hexio_read test.db 0 [file size test.db]]
++
++  set off [string first "023061018310" $hex]
++  set hex [string replace $hex $off [expr $off+11] 023061018370]
++  hexio_write test.db 0 $hex
++} {6144}
++
++sqlite3 db test.db
++
++do_catchsql_test 1.5 {
++  SELECT rowid FROM t WHERE t MATCH 'a'
++} {1 {fts5: corruption found reading blob 137438953481 from table "t"}}
++
++sqlite3_fts5_may_be_corrupt 0
++finish_test

diff --git a/sqlite.spec b/sqlite.spec
index 89ad195..af304c2 100644
--- a/sqlite.spec
+++ b/sqlite.spec
@@ -13,7 +13,7 @@
 Summary: Library that implements an embeddable SQL database engine
 Name: sqlite
 Version: %{rpmver}
-Release: 1%{?dist}
+Release: 2%{?dist}
 License: blessing
 URL: http://www.sqlite.org/
 
@@ -23,6 +23,7 @@ Source2: http://www.sqlite.org/%{year}/sqlite-autoconf-%{realver}.tar.gz
 # Support a system-wide lemon template
 Patch1: sqlite-3.6.23-lemon-system-template.patch
 Patch2: sqlite-3.49.0-fix-lemon-missing-cflags.patch
+Patch3: sqlite-3.51.2-CVE-2026-11822-CVE-2026-11824.patch
 
 BuildRequires: make
 BuildRequires: gcc gcc-c++
@@ -171,6 +172,7 @@ This package contains the analysis program for %{name}.
 %setup -q -a1 -n %{name}-src-%{realver}
 %patch -P 1 -p1
 %patch -P 2 -p1
+%patch -P 3 -p1
 
 # The atof test is failing on the i686 architecture, when binary configured with
 # --enable-rtree option. Failing part is text->real conversion and
@@ -350,6 +352,9 @@ make test
 %endif
 
 %changelog
+* Mon Aug 10 2026 Petr Khartskhaev <pkhartsk@redhat.com> - 3.51.2-2
+- Fix CVE-2026-11822 and CVE-2026-11824
+
 * Tue Jan 20 2026 Carl George <carlwgeorge@fedoraproject.org> - 3.51.2-1
 - Update to 3.51.2
 - https://www.sqlite.org/releaselog/3_51_2.html

^ permalink raw reply related	[flat|nested] only message in thread

only message in thread, other threads:[~2026-08-11 10:42 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-08-11 10:42 [rpms/sqlite] f44: Fix CVE-2026-11822 and CVE-2026-11824 Petr Khartskhaev

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox