Intel

AIKIDO-2026-964363

System.Data.SQLite is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)CVE-2025-29088 Published 5 days ago

56

Medium Risk

This Affects:

DOTNETSystem.Data.SQLite
1.0.115.5 - 1.0.119
Fixed in 2.0.1
Are you affected? Scan for Free

TL;DR

The bundled SQLite engine's sqlite3_db_config SQLITE_DBCONFIG_LOOKASIDE path multiplies lookaside slot size and count without promoting the product to 64-bit. Out-of-range arguments wrap that integer, so lookaside allocations can be undersized and the process crashes. There is no further bundled-engine release of this package. The engine fix applies a 64-bit multiply before allocating lookaside memory; applications need a native SQLite build that contains that change.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and the SQLITE_DBCONFIG_LOOKASIDE configuration path can be reached.

Background info

System.Data.SQLite is vulnerable to Denial of Service (DoS) in versions 1.0.115.5 - 1.0.119.

How to fix this

Upgrade the System.Data.SQLite or System.Data.SQLite.Core library to the patch version. From version 2.x on this library does not bundle native SQLite anymore.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform