An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain… (CVE-2025-70873)
An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.
AI Analysis
Technical Summary
CVE-2025-70873 is an information disclosure vulnerability in SQLite's zipfile extension, specifically in the zipfileInflate function. A remote attacker can exploit this by providing a crafted ZIP file, causing the application to disclose sensitive heap memory contents due to use of uninitialized resources (CWE-908). Red Hat has issued an advisory (RHSA-2026:7656) addressing this flaw with updated RPM packages for various SQLite components. The vulnerability has a low severity rating by Red Hat, with no known active exploitation. The CVSS score varies between Red Hat (3.3) and other sources (7.5) due to differing assessment contexts, but Red Hat's rating is authoritative for its products.
Potential Impact
Successful exploitation could lead to disclosure of sensitive heap memory information, potentially exposing confidential data. There is no impact on integrity or availability. The vulnerability requires a crafted ZIP file to trigger and involves reading uninitialized memory. No known exploits are currently active in the wild.
Mitigation Recommendations
Red Hat has released updated RPM packages containing fixes for this vulnerability. Users should apply these official updates to affected products. No additional mitigations are specified or required beyond applying the vendor-provided patches. Patch status is not explicitly stated in the advisory text provided, so users should consult the Red Hat advisory RHSA-2026:7656 for the latest remediation guidance.
An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain… (CVE-2025-70873)
Description
An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-70873 is an information disclosure vulnerability in SQLite's zipfile extension, specifically in the zipfileInflate function. A remote attacker can exploit this by providing a crafted ZIP file, causing the application to disclose sensitive heap memory contents due to use of uninitialized resources (CWE-908). Red Hat has issued an advisory (RHSA-2026:7656) addressing this flaw with updated RPM packages for various SQLite components. The vulnerability has a low severity rating by Red Hat, with no known active exploitation. The CVSS score varies between Red Hat (3.3) and other sources (7.5) due to differing assessment contexts, but Red Hat's rating is authoritative for its products.
Potential Impact
Successful exploitation could lead to disclosure of sensitive heap memory information, potentially exposing confidential data. There is no impact on integrity or availability. The vulnerability requires a crafted ZIP file to trigger and involves reading uninitialized memory. No known exploits are currently active in the wild.
Mitigation Recommendations
Red Hat has released updated RPM packages containing fixes for this vulnerability. Users should apply these official updates to affected products. No additional mitigations are specified or required beyond applying the vendor-provided patches. Patch status is not explicitly stated in the advisory text provided, so users should consult the Red Hat advisory RHSA-2026:7656 for the latest remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:7656
- Cve Count
- 1
- State
- PUBLISHED
Threat ID: 6a4049cf27e9c7971982aec9
Added to database: 06/27/2026, 22:08:15 UTC
Last enriched: 08/16/2026, 18:04:24 UTC
Last updated: 09/14/2026, 22:01:31 UTC
Views: 29
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.