Open Source Development

Power Open Source Development

Explore the open source tools and capabilities for building and deploying modern applications on IBM Power platforms including AIX, IBM i, and Linux.


#Power


#Power

 View Only
Expand all | Collapse all

Question about SQLite vulnerability CVE-2025-6965

  • 1.  Question about SQLite vulnerability CVE-2025-6965

    Posted Tue August 05, 2025 08:23 AM

    Hello,

    I see that SQLite is vulnerable to CVE-2025-6965.
    The problem occurs in versions of SQLite below 3.50.2; the current version of SQLite for AIX is 3.49.2-2.
    Version 3.49.2-2 was released on 31 July 2025; the CVE was published on 1 July 2025.
    I would therefore like to ask whether the current SQLite on AIX is affected by this CVE.
    If so, do you plan to release a new version of SQLite?

    Best regards,
    Adam



    ------------------------------
    Adam Waściński
    ------------------------------

    #AIXOpenSource


  • 2.  RE: Question about SQLite vulnerability CVE-2025-6965

    Posted Tue August 05, 2025 09:38 AM

    HI,
    We will update SQLite with the fixed version.  Thanks for informing us.

    Thanks
    Ranjit



    ------------------------------
    Ranjit Ranjan
    ------------------------------



  • 3.  RE: Question about SQLite vulnerability CVE-2025-6965

    Posted Fri August 08, 2025 08:17 AM

    Hi Ranjit,

    Is there any ETA on when the fix will be available?

    Thanks.



    ------------------------------
    Jowel Legaspi
    ------------------------------



  • 4.  RE: Question about SQLite vulnerability CVE-2025-6965

    Posted Fri August 08, 2025 09:29 AM

    Hi Ranjit,

    Is there any ETA on when the fix will be available?

    Thanks.



    ------------------------------
    Jowel Legaspi
    ------------------------------



  • 5.  RE: Question about SQLite vulnerability CVE-2025-6965

    Posted Fri August 08, 2025 10:47 AM

    Hi,
    We will update this discussion once it's available in tool box. You can expect in 3-4 weeks. 

    Thanks
    Ranjit



    ------------------------------
    Ranjit Ranjan
    ------------------------------



  • 6.  RE: Question about SQLite vulnerability CVE-2025-6965

    Posted Mon August 25, 2025 03:17 AM

    Good day Ranjit

    Do you have a date yet for the release?  I have several systems that were flagged with the memory corruption vulnerability.



    ------------------------------
    Willem van Wyk
    ------------------------------



  • 7.  RE: Question about SQLite vulnerability CVE-2025-6965

    Posted Thu August 28, 2025 03:26 AM

    Hi All, 

    SQLite 3.50.4 is available for upgrade. Please update your systems.

    Thanks
    Ranjit



    ------------------------------
    Ranjit Ranjan
    ------------------------------



  • 8.  RE: Question about SQLite vulnerability CVE-2025-6965

    Posted 8 days ago

    Hello Ranjit,

    After Updating the SQlite to 3.50.4 on AIX 7.2 TL 5 SP10 , we face one challenge i.e we cant able to reboot the OS. Kindly suggest do we have any fix for same if so kindly provide us the solution to mitigate this



    ------------------------------
    Sandeep Navalkar
    ------------------------------



  • 9.  RE: Question about SQLite vulnerability CVE-2025-6965

    Posted 8 days ago

    Hi Sandeep,
    Please elaborate the problem you are facing with OS reboot. Which command is failing/hanging ?


    Thanks
    Ranjit



    ------------------------------
    Ranjit Ranjan
    ------------------------------



  • 10.  RE: Question about SQLite vulnerability CVE-2025-6965

    Posted 8 days ago

    After upgrading the SQlite version from sqlite-3.32.1-1.ppc to sqlite-3.50.4-1.ppc and upgrade its dependent package as below on AIX 7.2 TL05 SP10 , we cant able to reboot the server . Kindly suggest if we miss something

    Old version:

    readline-8.0-2.ppc
    sqlite-3.32.1-1.ppc
    ncurses-6.2-1.ppc

    New Version

    readline-8.2-1.ppc
    sqlite-3.50.4-1.ppc
    ncurses-6.5-1.ppc

    receiving mentioned error in console log file

    0 Sun Dec 14 23:00:02 CET 2025

    0 Sun Dec 14 23:00:02 CET 2025 SHUTDOWN PROGRAM

    0 Sun Dec 14 23:00:02 CET 2025 Sun Dec 14 23:00:02 CET 2025

    0 Sun Dec 14 23:00:02 CET 2025 Arret des bases de donnees INFORMIX...

    0 Sun Dec 14 23:00:07 CET 2025 /etc/rc.shutdown failed. Shutdown aborting



    ------------------------------
    Sandeep Navalkar
    ------------------------------



  • 11.  RE: Question about SQLite vulnerability CVE-2025-6965

    Posted 8 days ago

    Kindly let me know is it known issue or we are missing here something as our NIM server also facing the above issue for AIX 7.2 TL 05 SP 10 



    ------------------------------
    Sandeep Navalkar
    ------------------------------



  • 12.  RE: Question about SQLite vulnerability CVE-2025-6965

    Posted 8 days ago

    @Jowel Legaspi: can you please let me know was the SQlite update implemented successfully for you



    ------------------------------
    Sandeep Navalkar
    ------------------------------



  • 13.  RE: Question about SQLite vulnerability CVE-2025-6965

    Posted 8 days ago

    Hi Sandeep,

    I don't see the relationship between shutdown and Sqlite pkg. 
    Can you tell me how you are pointing out that it's related to Sqlite as other pkgs are also updated in your system.

    I would suggest to create a case with IBM support and then IBM support will do initial debugging for shutdown hanging. 

    Thanks
    Ranjit



    ------------------------------
    Ranjit Ranjan
    ------------------------------



  • 14.  RE: Question about SQLite vulnerability CVE-2025-6965

    Posted 8 days ago

    Hello Ranjit,

    We logged a case with IBM but IBM suggest that its open-source package so support will not be provided, but after downgrading the package to original version reboot command is working fine as expected



    ------------------------------
    Sandeep Navalkar
    ------------------------------



  • 15.  RE: Question about SQLite vulnerability CVE-2025-6965

    Posted 7 days ago

    Hello Ranjit,

    can you please help on same , kindly let me know if any other user faces such issue for AIX 7.2 TL05 SP 10 .. as it didnt work for SP11 also



    ------------------------------
    Sandeep Navalkar
    ------------------------------



  • 16.  RE: Question about SQLite vulnerability CVE-2025-6965

    Posted 7 days ago

    Hi Sandeep,

    I still don't think any relationship between the open source packages you have installed and the shutdown command.

    I too have the same environment and don't see any issue.

    # oslevel -s
    7200-05-10-2520

    (0) root @ beech14: /
    # rpm -qa | grep -E "readline|sqlite|ncurses"
    ncurses-6.5-1.ppc
    readline-8.2-1.ppc
    sqlite-3.50.4-1.ppc

    Looking into the log you sent.

    Arret des bases de donnees INFORMIX and it's English conversion is Shutdown of the INFORMIX databases.

    Can you check if INFORMIX database is also shutting down correctly ?



    ------------------------------
    SANGAMESH
    ------------------------------



  • 17.  RE: Question about SQLite vulnerability CVE-2025-6965

    Posted 7 days ago

    Hello Sangamesh,

    Thanks for your help we tried the same Sqlite version on our NIM server where no application was hosted, there also reboot and shutdown command not working.

    if possible, can you please help me to share the cat /etc/rc.shutdown O/P from your environment, so we can match the same and try to identify the root cause



    ------------------------------
    Sandeep Navalkar
    ------------------------------



  • 18.  RE: Question about SQLite vulnerability CVE-2025-6965

    Posted yesterday

    Hello Sangamesh,

    Can you please let me know how you update the SQlite version did you done fresh installation or did you update from old version to new version.

    kindly let us know the steps you followed to update the SQlite to latest version



    ------------------------------
    Sandeep Navalkar
    ------------------------------



  • 19.  RE: Question about SQLite vulnerability CVE-2025-6965

    Posted 8 hours ago

    Hello Sangamesh,

    Can you please update on same



    ------------------------------
    Sandeep Navalkar
    ------------------------------



  • 20.  RE: Question about SQLite vulnerability CVE-2025-6965

    Posted 7 hours ago

    Hi Sandeep,

    If possible can you try comparing the logs with older version of sqlite and logs after update to sqlite ?

    Can you also let me know using what command you are trying to shutdown.

    After the failed shutdown can you can try to get some info with "errpt -a"



    ------------------------------
    SANGAMESH
    ------------------------------