CVE-2024-0232: Fedoraproject Extra Packages For Enterprise Linux

Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.

Affected products

  • Fedoraproject Extra Packages For Enterprise Linux: version 8.0 only
  • Fedoraproject Fedora: version 39 only
  • Red Hat Enterprise Linux: version 8.0 only; version 9.0 only
  • Sqlite Sqlite: from 3.43.0, before 3.43.2 (fixed in 3.43.2)

Published 2024-01-16. Last modified 2026-06-17.