Control: tags -1 + confirmed

On Sat, 2026-01-24 at 11:06 +0100, László Böszörményi (GCS) wrote:
> There's a security fix for sqlite3 which doesn't warrant a DSA and a
> packaging glitch fix.
> 
> [ Reason ]
> The security fix is an integer overflow in the FTS5 extension, not in
> the library itself. The risk is an out of bounds write, but the data
> is only partially controlled.
> Packaging misses the pkgconf build dependency to link the ICU library
> to the ICU extension of the sqlite3. This fixes the extension
> loading.

Please go ahead.

Regards,

Adam

Reply via email to