PageSourceSearch

https://docs-spectrocloud.netlify.app/assets/js/537f8490.0541350e.js

js docs-spectrocloud.netlify.app collected 2026-10-03 10:43:20 UTC 8,458 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunkspectro_cloud_docs=self.webpackChunkspectro_cloud_docs||[]).push([["15152"],{610799:function(e,t,i){i.r(t),i.d(t,{frontMatter:()=>l,toc:()=>d,default:()=>h,metadata:()=>r,assets:()=>a,contentTitle:()=>c});var r=JSON.parse('{"id":"security-bulletins/reports/pc-cve-2025-6965","title":"CVE-2025-6965","description":"Lifecycle of CVE-2025-6965","source":"@site/docs/docs-content/security-bulletins/reports/pc-cve-2025-6965.md","sourceDirName":"security-bulletins/reports","slug":"/security-bulletins/reports/pc-cve-2025-6965","permalink":"/security-bulletins/reports/pc-cve-2025-6965","draft":false,"unlisted":false,"editUrl":"https://github.com/spectrocloud/librarium/blob/master/docs/docs-content/security-bulletins/reports/pc-cve-2025-6965.md","tags":[{"inline":true,"label":"security","permalink":"/tags/security"},{"inline":true,"label":"cve","permalink":"/tags/cve"}],"version":"current","lastUpdatedAt":null,"frontMatter":{"sidebar_label":"CVE-2025-6965","title":"CVE-2025-6965","description":"Lifecycle of CVE-2025-6965","sidebar_class_name":"hide-from-sidebar","hide_table_of_contents":false,"toc_max_heading_level":2,"tags":["security","cve"]},"sidebar":"docSidebar","previous":{"title":"CVE-2025-68973","permalink":"/security-bulletins/reports/pc-cve-2025-68973"},"next":{"title":"CVE-2025-8176","permalink":"/security-bulletins/reports/pc-cve-2025-8176"}}'),n=i(474848),s=i(884429);let l={sidebar_label:"CVE-2025-6965",title:"CVE-2025-6965",description:"Lifecycle of CVE-2025-6965",sidebar_class_name:"hide-from-sidebar",hide_table_of_contents:!1,toc_max_heading_level:2,tags:["security","cve"]},c,a={},d=[{value:"CVE Details",id:"cve-details",level:2},{value:"Initial Publication",id:"initial-publication",level:2},{value:"Last Update",id:"last-update",level:2},{value:"Third Party Dependency",id:"third-party-dependency",level:2},{value:"NIST CVE Summary",id:"nist-cve-summary",level:2},{value:"CVE Severity",id:"cve-severity",level:2},{value:"Our Official Summary",id:"our-official-summary",level:2},{value:"Status",id:"status",level:2},{value:"Affected Products & Versions",id:"affected-products--versions",level:2},{value:"Revision History",id:"revision-history",level:2}];function o(e){let t={a:"a",h2:"h2",li:"li",p:"p",table:"table",tbody:"tbody",td:"td",th:"th",thead:"thead",tr:"tr",ul:"ul",...(0,s.R)(),...e.components};return(0,n.jsxs)(n.Fragment,{children:[(0,n.jsx)(t.h2,{id:"cve-details",children:"CVE Details"}),"\n",(0,n.jsxs)(t.p,{children:["Visit the official vulnerability details page for ",(0,n.jsx)(t.a,{href:"https://nvd.nist.gov/vuln/detail/cve-2025-6965",children:"CVE-2025-6965"})," to learn more."]}),"\n",(0,n.jsx)(t.h2,{id:"initial-publication",children:"Initial Publication"}),"\n",(0,n.jsx)(t.p,{children:"07/17/2025"}),"\n",(0,n.jsx)(t.h2,{id:"last-update",children:"Last Update"}),"\n",(0,n.jsx)(t.p,{children:"04/23/2026"}),"\n",(0,n.jsx)(t.h2,{id:"third-party-dependency",children:"Third Party Dependency"}),"\n",(0,n.jsx)(t.p,{children:"sqlite-libs"}),"\n",(0,n.jsx)(t.h2,{id:"nist-cve-summary",children:"NIST CVE Summary"}),"\n",(0,n.jsx)(t.p,{children:"There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above."}),"\n",(0,n.jsx)(t.h2,{id:"cve-severity",children:"CVE Severity"}),"\n",(0,n.jsx)(t.p,{children:(0,n.jsx)(t.a,{href:"https://nvd.nist.gov/vuln/detail/cve-2025-6965",children:"9.8"})}),"\n",(0,n.jsx)(t.h2,{id:"our-official-summary",children:"Our Official Summary"}),"\n",(0,n.jsx)(t.p,{children:"A memory corruption vulnerability has been identified in SQLite versions earlier than 3.50.2. The issue occurs when the number of aggregate terms in a SQL query exceeds the number of available columns, potentially leading to crashes, unpredictable behavior, data corruption, or in some cases, arbitrary code execution."}),"\n",(0,n.jsx)(t.p,{children:"This vulnerability has been reported in certain upstream images used by the VM Orchestrator component. It does not affect cluster
1s that do not use this functionality."}),"\n",(0,n.jsxs)(t.ul,{children:["\n",(0,n.jsx)(t.li,{children:"In the affected images, multiple security controls are already in place:"}),"\n",(0,n.jsx)(t.li,{children:"The images are not accessible externally, limiting exposure."}),"\n",(0,n.jsx)(t.li,{children:"An attacker would require privileged access within the cluster to attempt exploitation."}),"\n"]}),"\n",(0,n.jsx)(t.p,{children:"The containers do not permit arbitrary code execution, further mitigating risk."}),"\n",(0,n.jsx)(t.p,{children:"As a result, the practical impact of this vulnerability is low, with the containerized deployment model significantly reducing the overall attack surface."}),"\n",(0,n.jsx)(t.h2,{id:"status",children:"Status"}),"\n",(0,n.jsx)(t.p,{children:"Ongoing"}),"\n",(0,n.jsx)(t.h2,{id:"affected-products--versions",children:"Affected Products & Versions"}),"\n",(0,n.jsxs)(t.table,{children:[(0,n.jsx)(t.thead,{children:(0,n.jsxs)(t.tr,{children:[(0,n.jsx)(t.th,{children:"Version"}),(0,n.jsx)(t.th,{children:"Palette Enterprise"}),(0,n.jsx)(t.th,{children:"Palette Enterprise Airgap"}),(0,n.jsx)(t.th,{children:"VerteX"}),(0,n.jsx)(t.th,{children:"VerteX Airgap"})]})}),(0,n.jsxs)(t.tbody,{children:[(0,n.jsxs)(t.tr,{children:[(0,n.jsx)(t.td,{children:"4.8.52"}),(0,n.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,n.jsx)(t.td,{children:"\u2705 No Impact"}),(0,n.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,n.jsx)(t.td,{children:"\u2705 No Impact"})]}),(0,n.jsxs)(t.tr,{children:[(0,n.jsx)(t.td,{children:"4.7.29"}),(0,n.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,n.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,n.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,n.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"})]}),(0,n.jsxs)(t.tr,{children:[(0,n.jsx)(t.td,{children:"4.6.41"}),(0,n.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,n.jsx)(t.td,{children:"\u2705 No Impact"}),(0,n.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,n.jsx)(t.td,{children:"\u2705 No Impact"})]})]})]}),"\n",(0,n.jsx)(t.h2,{id:"revision-history",children:"Revision History"}),"\n",(0,n.jsxs)(t.table,{children:[(0,n.jsx)(t.thead,{children:(0,n.jsxs)(t.tr,{children:[(0,n.jsx)(t.th,{children:"Date"}),(0,n.jsx)(t.th,{children:"Revision"})]})}),(0,n.jsxs)(t.tbody,{children:[(0,n.jsxs)(t.tr,{children:[(0,n.jsx)(t.td,{children:"08/18/2025"}),(0,n.jsx)(t.td,{children:"Official summary revised: A memory corruption vulnerability has been identified in SQLite versions earlier than 3.50.2. The issue occurs when the number of aggregate terms in a SQL query exceeds the number of available columns, potentially leading to crashes, unpredictable behavior, data corruption, or in some cases, arbitrary code execution.This vulnerability has been reported in certain upstream images used by the VM Orchestrator component. It does not affect clusters that do not use this functionality.- In the affected images, multiple security controls are already in place:- The images are not accessible externally, limiting exposure.- An attacker would require privileged access within the cluster to attempt exploitation.The containers do not permit arbitrary code execution, further mitigating risk.As a result, the practical impact of this vulnerability is low, with the containerized deployment model significantly reducing the overall attack surface."})]}),(0,n.jsxs)(t.tr,{children:[(0,n.jsx)(t.td,{children:"07/31/2025"}),(0,n.jsx)(t.td,{children:"Status changed from Open to Ongoing"})]}),(0,n.jsxs)(t.tr,{children:[(0,n.jsx)(t.td,{children:"07/31/2025"}),(0,n.jsx)(t.td,{children:"Official summary added"})]}),(0,n.jsxs)(t.tr,{children:[(0,n.jsx)(t.td,{children:"07/23/2025"}),(0,n.jsx)(t.td,{children:"Advisory assigned with CRITICAL severity"})]})]})]})]})}function h(e={}){let{wrapper:t}={...(0,s.R)(),...e.components};return t?(0,n.jsx)(t,{...e,children:(0,n.jsx)(o,{...e})}):o(e)}},884429:function(e,t,i){i.d(t,{R:()=>l,x:()=>c});var r=i(296540);let n={},s=r.createContext(n);function l(e){let t=r.useContext(s);return r.useMemo(function(){return"function"==typeof e?e(t):{...t,...e}},[t,e])}function c(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(n):e.components||n:l(e.components),r.createElement(s.Provider,{value:t},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.