CVE-2024-0232: Fedoraproject Extra Packages For Enterprise Linux
Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.
A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.
Affected products
- Fedoraproject Extra Packages For Enterprise Linux: version 8.0 only
- Fedoraproject Fedora: version 39 only
- Red Hat Enterprise Linux: version 8.0 only; version 9.0 only
- Sqlite Sqlite: from 3.43.0, before 3.43.2 (fixed in 3.43.2)
Published 2024-01-16. Last modified 2026-06-17.