Sploitus

CVE-2026-11824

No indexed exploits for CVE-2026-11824 yet

SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attackers can trigger an integer underflow in fts5ChunkIterate() causing an inflated remaining byte count during FTS5 MATCH query processing, leading to a heap buffer overflow of attacker-controlled data in applications compiled with SQLITE_ENABLE_FTS5.

Affected products
Linuxmint, Rocky Linux, Sqlite, Ubuntu
Sqlite
< 3.53.2
Fix
Available
CVSS 4.0
8.5 HIGH
CVSS 3.1
7.8 HIGH
EPSS
0.2% (7th percentile)
Weakness
CWE-122
NVD status
Analyzed
Published
2026-06-09
CVE-2026-11824 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-11824 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-11824 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.