¡¾·ì϶¹«¸æ¡¿SQLite FTS5 ÕûÊýÒç³ö·ì϶ (CVE-2025-7709)

°ä²¼¹¦·ò 2025-09-09

Ò»¡¢¡¢·ì϶¸ÅÊö


·ì϶Ãû³Æ

SQLite FTS5 ÕûÊýÒç³ö·ì϶

CVE   ID

CVE-2025-7709

·ì϶ÀàÐÍ

»º³åÇøÒç³ö

·¢ÏÖ¹¦·ò

2025-09-09

·ì϶ÆÀ·Ö

6.9

·ì϶µÈ¼¶

ÖÐΣ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

µÍ

ÀûÓÃÄѶÈ

¸ß

Óû§½»»¥

±ØÒª

PoC/EXP

Òѹ«¿ª

ÔÚÒ°ÀûÓÃ

δ·¢ÏÖ


SQLite FTS5£¨È«Îı¾ËÑË÷5£©ÊÇSQLiteÊý¾Ý¿âµÄÀ©´óÄ£¿£¿é£¬£¬£¬ÓÃÓÚʵÏÖ¸ßЧµÄÈ«ÎÄËÑË÷Ö°ÄÜ¡£¡£¡£¡£¡£FTS5ÌṩÁ˶ÔÎı¾Êý¾ÝµÄË÷ÒýÖ§³Ö£¬£¬£¬ÔÊÐíÓû§Ö´Ðи´ÔÓµÄÎı¾²éÎÊ£¬£¬£¬ÈçÄ£º£º£ºýÆ¥Åä¡¢¡¢¶ÌÓïËÑË÷ºÍÈ¨ÖØÅÅÐò¡£¡£¡£¡£¡£ËüʹÓõ¹ÅÅË÷ÒýÀ´´æ´¢´ÊÌõ¼°Æä³öÏÖµØÎ»£¬£¬£¬´Ó¶ø¼Ó¿ì²éÎʹý³Ì¡£¡£¡£¡£¡£FTS5Ö§³Ö¶àÖÖ˵»°µÄ·Ö´ÊºÍËÑË÷ÅäÖ㬣¬£¬ºÏÓÃÓÚ±ØÒª¶Ô´óÁ¿Îı¾Êý¾Ý½øÐм±¾ç¼ìË÷µÄÀûÓᣡ£¡£¡£¡£ÓëSQLiteµÄÆäËûÖ°ÄܼæÈÝ£¬£¬£¬FTS5±»¿í·ºÀûÓÃÓÚǶÈëʽÊý¾Ý¿âϵͳÖС£¡£¡£¡£¡£


2025Äê9ÔÂ9ÈÕ£¬£¬£¬OG¶«·½Ìü¼¯ÍÅVSRC¼à²âµ½Ò»¸ö´æÔÚÓÚSQLite FTS5À©´óÖеÄÕûÊýÒç³ö·ì϶¡£¡£¡£¡£¡£µ±ÍÆËãÂß¼­É¾³ýÖ¸ÕëÊý×éµÄ¾Þϸ²¢½«Æä½Ø¶ÏΪ32λÕûÊýʱ£¬£¬£¬¾Í»á²úÉú´Ë·ì϶¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»Í¨¹ý²Ù¿ØÊý¾Ý£¬£¬£¬ÀûÓô˷ì϶µ¼ÖÂÖ¸Ïò²¿ÃÅÊÜ¿ØÊý¾ÝµÄÖ¸ÕëÔ½½çдÈ룬£¬£¬´Ó¶ø¿ÉÄܵ¼ÖÂÄÚ´æ°Ü»µ»òËÁÒâ´úÂëÖ´ÐС£¡£¡£¡£¡£·ì϶ÆÀ·Ö6.9·Ö£¬£¬£¬·ì϶¼¶±ðÖÐΣ¡£¡£¡£¡£¡£


¶þ¡¢¡¢Ó°ÏìÁìÓò


SQLite <= 3.49.1


Èý¡¢¡¢°²È«´ëÊ©


3.1 Éý¼¶°æ±¾


ÒѰ䲼ÐÞ¸´°æ±¾£¬£¬£¬Ç뽫SQLiteÉý¼¶µ½Èçϰ汾¡£¡£¡£¡£¡£
SQLite >= 3.50


ÏÂÔØÁ´½Ó£º£º£ºhttps://www.sqlite.org/download.html/


3.2 һʱ´ëÊ©


ÔÝÎÞ¡£¡£¡£¡£¡£


3.3 ͨÓý¨Òé


? ¶¨ÆÚ¸üÐÂϵͳ²¹¶¡£¬£¬£¬Ï÷¼õϵͳ·ì϶£¬£¬£¬ÌáÉý·þÎñÆ÷µÄ°²È«ÐÔ¡£¡£¡£¡£¡£
¼ÓǿϵͳºÍÍøÂçµÄ½Ó¼û½ÚÖÆ£¬£¬£¬Åú¸Ä·À»ðǽսÊõ£¬£¬£¬¹Ø±Õ·Ç±ØÒªµÄÀûÓö˿ڻò·þÎñ£¬£¬£¬Ï÷¼õ½«Î£ÏÕ·þÎñ£¨ÈçSSH¡¢¡¢RDPµÈ£©Â¶³öµ½¹«Íø£¬£¬£¬Ï÷¼õ¹¥»÷Ãæ¡£¡£¡£¡£¡£
ʹÓÃÆóÒµ¼¶°²È«²úÆ·£¬£¬£¬ÌáÉýÆóÒµµÄÍøÂ簲ȫ»úÄÜ¡£¡£¡£¡£¡£
¼ÓǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬£¬ÆôÓöà³É·ÖÈÏÖ¤»úÖÆºÍ×îСȨÏÞ×¼Ôò£¬£¬£¬Óû§ºÍÈí¼þȨÏÞӦά³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£

ÆôÓÃÇ¿ÃÜÂëÕ½Êõ²¢ÉèÖÃΪ¶¨ÆÚÅú¸Ä¡£¡£¡£¡£¡£


3.4 ²Î¿¼Á´½Ó


https://github.com/google/security-research/security/advisories/GHSA-v2c8-vqqp-hv3g
https://www.openwall.com/lists/oss-security/2025/09/06/2/