CVE-2019-16168: Canonical Ubuntu Linux

Medium severity, CVSS 6.5. EPSS: 4.3% chance of exploitation in the next 30 days.

In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner."

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 16.04 only; version 18.04 only; version 19.04 only; version 19.10 only
  • Debian Debian Linux: version 9.0 only
  • Fedoraproject Fedora: version 30 only
  • McAfee Policy Auditor: before 6.5.1 (fixed in 6.5.1)
  • Netapp Active Iq Unified Manager: from 7.3; from 9.5
  • Netapp E-Series Santricity OS Controller: from 11.0.0, up to and including 11.60.3
  • Netapp Oncommand Insight: affected versions not specified
  • Netapp Oncommand Workflow Automation: affected versions not specified
  • Netapp Ontap Select Deploy Administration Utility: affected versions not specified
  • Netapp Santricity Unified Manager: affected versions not specified
  • Netapp Steelstore Cloud Integrated Storage: affected versions not specified
  • Oracle Communications Design Studio: version 7.3.4.3.0 only; version 7.3.5.5.0 only; version 7.4.0.4.0 only
  • Oracle JDK: version 1.8.0 only
  • Oracle JRE: version 1.8.0 only
  • Oracle MySQL: from 8.0.0, up to and including 8.0.18
  • Oracle Outside In Technology: version 8.5.4 only
  • Oracle Solaris: version 11 only
  • Oracle ZFS Storage Appliance: version 8.8 only
  • Sqlite Sqlite: from 3.8.5, up to and including 3.29.0
  • Tenable Nessus Agent: up to and including 8.2.3

Published 2019-09-09. Last modified 2026-06-17.