Ubuntu Security Notices USN-8480-1 USN-8480-1: SQLite vulnerabilities Publication date 29 June 2026 Overview Several security issues were fixed in SQLite. Releases 26.04 LTS 25.10 24.04 LTS 22.04 LTS Open side navigation Close side navigation Packages Details Update instructions References Packages sqlite3 - C library that implements an SQL database engine Details It was discovered that SQLite incorrectly handled certain memory operations in the FTS5 full-text search extension. An attacker could use this issue to cause SQLite to crash, resulting in a denial of service, or possibly execute arbitrary code. It was discovered that SQLite incorrectly handled certain memory operations in the FTS5 full-text search extension. An attacker could use this issue to cause SQLite to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions In general, a standard system update will make all the necessary changes. Learn more about how to get the fixes. The problem can be corrected by updating your system to the following package versions: Ubuntu Release Package Version 26.04 LTS resolute libsqlite3-0 – 3.46.1-9ubuntu0.1 25.10 questing libsqlite3-0 – 3.46.1-8ubuntu0.1 24.04 LTS noble libsqlite3-0 – 3.45.1-1ubuntu2.6 22.04 LTS jammy libsqlite3-0 – 3.37.2-2ubuntu0.6 Reduce your security exposure Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines. Get Ubuntu Pro References CVE-2026-11824 CVE-2026-11822 CVE-2026-11824 CVE-2026-11822
Two memory handling vulnerabilities in the SQLite FTS5 extension (CVE-2026-11824 and CVE-2026-11822, both CVSS 7.8 HIGH) can lead to denial of service or arbitrary code execution. The vulnerabilities affect SQLite versions prior to 3.53.2. The fix requires upgrading SQLite to version 3.53.2.