¡¾·ì϶¹«¸æ¡¿SQLite FTS5 ÕûÊýÒç¶Âí½Å (CVE-2025-7709)

°ä²¼¹¦·ò 2025-09-09

Ò»¡¢·ì϶¸ÅÊö


·ìϼûû³Æ

SQLite FTS5 ÕûÊýÒç¶Âí½Å

CVE   ID

CVE-2025-7709

·ì϶ÀàÐÍ

»º³åÇøÒç³ö

·¢ÏÖ¹¦·ò

2025-09-09

·ì϶ÆÀ·Ö

6.9

·ì϶µÈ¼¶

ÖÐΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

µÍ

ÀûÓÃÄѶÈ

¸ß

Óû§½»»¥

±ØÒª

PoC/EXP

Òѹ«¿ª

ÔÚÒ°ÀûÓÃ

δ·¢ÏÖ


SQLite FTS5£¨È«Îı¾ËÑË÷5£©ÊÇSQLiteÊý¾Ý¿âµÄÀ©´óÄ£¿é£¬ÓÃÓÚʵÏÖ¸ßЧµÄÈ«ÎÄËÑË÷Ö°ÄÜ¡£FTS5ÌṩÁ˶ÔÎı¾Êý¾ÝµÄË÷ÒýÖ§³Ö£¬ÔÊÐíÓû§Ö´Ðи´ÔÓµÄÎı¾²éÎÊ£¬ÈçÍÌÍÂÆ¥Åä¡¢¶ÌÓïËÑË÷ºÍȨ³ÁÅÅÐò¡£ËüʹÓõ¹ÅÅË÷ÒýÀ´´æ´¢´ÊÌõ¼°Æä³öÏÖµØÎ»£¬´Ó¶ø¼Ó¿ì²éÎʹý³Ì¡£FTS5Ö§³Ö¶àÖÖ˵»°µÄ·Ö´ÊºÍËÑË÷ÅäÖ㬺ÏÓÃÓÚ±ØÒª¶Ô´óÁ¿Îı¾Êý¾Ý½øÐм±¾ç¼ìË÷µÄÀûÓá£ÓëSQLiteµÄÆäËûÖ°ÄܼæÈÝ£¬FTS5±»¿í·ºÀûÓÃÓÚǶÈëʽÊý¾Ý¿âϵͳÖС£


2025Äê9ÔÂ9ÈÕ£¬GA»Æ½ð¼×¼¯ÍÅVSRC¼à²âµ½Ò»¸ö´æÔÚÓÚSQLite FTS5À©´óÖеÄÕûÊýÒç¶Âí½Å¡£µ±ÍÆËãÂß¼­É¾³ýÖ¸ÕëÊý×éµÄ´óÓײ¢½«Æä½Ø¶ÏΪ32λÕûÊýʱ£¬¾Í»á²úÉú´Ë·ì϶¡£¹¥»÷ÕßÄܹ»Í¨¹ý²Ù¿ØÊý¾Ý£¬ÀûÓô˷ì϶µ¼ÖÂÖ¸Ïò²¿ÃÅÊÜ¿ØÊý¾ÝµÄÖ¸ÕëÔ½½çдÈ룬´Ó¶ø¿ÉÄܵ¼ÖÂÄÚ´æ°Ü»µ»òËÁÒâ´úÂëÖ´ÐС£·ì϶ÆÀ·Ö6.9·Ö£¬·ì϶¼¶±ðÖÐΣ¡£


¶þ¡¢Ó°ÏìÁìÓò


SQLite <= 3.49.1


Èý¡¢°²È«´ëÊ©


3.1 Éý¼¶°æ±¾


ÒѰ䲼½¨¸´°æ±¾£¬Ç뽫SQLiteÉý¼¶µ½Èçϰ汾¡£
SQLite >= 3.50


ÏÂÔØÁ´½Ó£ºhttps://www.sqlite.org/download.html/


3.2 һʱ´ëÊ©


ÔÝÎÞ¡£


3.3 ͨÓý¨Òé


? ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬Ï÷¼õϵͳ·ì϶£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£
¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÔ죬Åú¸Ä·À»ðǽսÊõ£¬¹Ø¹Ø·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬Ï÷¼õ¹¥»÷Ãæ¡£
ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£
¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ÆôÓöà³É·ÖÈÏÖ¤»úÔìºÍ×îÓ×ȨÏÞ×¼Ôò£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£

ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£


3.4 ²Î¿¼Á´½Ó


https://github.com/google/security-research/security/advisories/GHSA-v2c8-vqqp-hv3g
https://www.openwall.com/lists/oss-security/2025/09/06/2/