CVE-2021-36690
SQLite vulnerability analysis and mitigation

Overview

A segmentation fault vulnerability was discovered in SQLite version 3.36.0, specifically in the sqlite3.exe command-line component's idxGetTableInfo function (CVE-2021-36690). The vulnerability was reported on July 8, 2021, and affects the command-line interface when processing crafted SQL queries (SQLite Forum). The vendor has disputed the relevance of this report, noting that sqlite3.exe users already have full privileges and are intentionally allowed to execute commands (CVE Mitre).

Technical details

The vulnerability manifests as a segmentation fault in the idxGetTableInfo function when processing specially crafted SQL queries. The issue occurs during memory access operations, specifically triggered by a READ memory access pointing to the zero page, as indicated by AddressSanitizer output (SQLite Forum). It's important to note that this vulnerability only affects the command-line tool sqlite3.exe and does not impact the core SQLite library.

Impact

The vulnerability can cause a denial-of-service condition through application crashes when processing specially crafted SQL queries (Apple Support). However, the impact is limited since it only affects the command-line interface where users already have full privileges.

Mitigation and workarounds

The issue was addressed with improved checks in subsequent releases (Apple Support). The fix was implemented in SQLite commit b1e0c22ec981cf5f, specifically addressing the issue in the experimental 'Expert' extension (SQLite Forum).

Additional resources


SourceThis report was generated using AI

Related SQLite vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-6965HIGH7.2
  • SQLiteSQLite
  • rust-analyzer
NoYesJul 15, 2025
CVE-2025-7709MEDIUM6.9
  • SQLiteSQLite
  • sqlite-libs
NoYesSep 08, 2025
CVE-2025-7458MEDIUM6.9
  • SQLiteSQLite
  • nodejs:22::v8-12.4-devel
NoYesJul 29, 2025
ELSA-2025-20936HIGHN/A
  • SQLiteSQLite
  • sqlite
NoYesNov 25, 2025
CVE-2025-52099N/AN/A
  • SQLiteSQLite
  • mingw32-sqlite-static
NoYesOct 24, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management