Red Hat issued Important SQLite updates for RHEL 8, RHEL 9, and RHEL 10 to remediate CVE-2026-11822 and CVE-2026-11824 in the FTS5 full-text-search component. Crafted FTS5 data can trigger arbitrary code execution through CVE-2026-11822; CVE-2026-11824 is a heap-based buffer overflow that can lead to arbitrary code execution or a crash. The advisories cover standard and extended-support RHEL deployments, including RHEL 8.4, 8.6, 8.8, and 8.10 channels, across x86_64, aarch64, ppc64le, and s390x where applicable.
Organizations should prioritize updating affected SQLite packages through Red Hat package management, including version 3.26.0-21.el8_10 for standard RHEL 8/8.10 ELS, 3.34.1-11.el9_8 for RHEL 9, and 3.46.1-6.el10_2 for RHEL 10, while applying the channel-specific RHEL 8 builds for AUS and EUS deployments. Rocky Linux 8 also released corresponding SQLite updates, and scanners such as Nessus can identify exposed systems through installed-package version checks; these checks do not actively validate exploitability.

See real exploitation activity before you spend the cycle.
15 events from the most recent confirmed update back to the earliest known activity.
Miracle Linux published advisory AXSA-2026-1681 for Miracle Linux 9, updating sqlite, sqlite-libs, and sqlite-devel to address CVE-2026-11822 and CVE-2026-11824. The advisory reported no known exploits.
Unity Linux advisory UTSA-2026-104748 remediates CVE-2026-11822 in affected SQLite packages on Unity Linux 20. The referenced patch was published without any known public exploits reported.
Red Hat published Important advisory RHSA-2026:59956 for RHEL 9.6 Extended Update Support systems, updating sqlite-devel and sqlite-libs to remediate SQLite FTS5 vulnerabilities CVE-2026-11822 and CVE-2026-11824. The advisory reported no known exploits.
Miracle Linux issued advisory AXSA-2026-1658 for Miracle Linux 8, updating SQLite-related packages including lemon, sqlite, sqlite-devel, sqlite-doc, and sqlite-libs to address CVE-2026-11822 and CVE-2026-11824. The advisory reported no known exploits at publication.
Oracle published ELSA-2026-58938 for Oracle Linux 8, updating SQLite-related packages including lemon, sqlite-devel, sqlite-doc, and sqlite-libs to address CVE-2026-11822 and CVE-2026-11824. The advisory includes Oracle Linux 8.10 BaseOS Patch and reported no known public exploits.
Rocky Linux published RLSA-2026:54371 for Node.js 24 packages on Rocky Linux 8. The update remediated six flaws affecting SQLite, brace-expansion, and ip-address, including the SQLite FTS5 vulnerabilities CVE-2026-11822 and CVE-2026-11824.
Rocky Linux published RLSA-2026-58938 for Rocky Linux 8 SQLite and Lemon packages. The update referenced CVE-2026-11822 and CVE-2026-11824; the advisory reported no known public exploits.
AlmaLinux published ALSA-2026:58927 for AlmaLinux 10, updating sqlite-libs and sqlite-devel to address SQLite FTS5 vulnerabilities CVE-2026-11822 and CVE-2026-11824. The advisory reported no known public exploits.
Red Hat issued Important advisory RHSA-2026:59024 for RHEL 8.4 Advanced Update Support and Extended Life Cycle Long Life systems on x86_64. The advisory supplied SQLite 3.26.0-13.el8_4.2 packages to remediate the two FTS5 vulnerabilities.
Red Hat issued Important advisory RHSA-2026:59020 for RHEL 8.6 Advanced Update Support and Extended Life Cycle Long Life deployments on x86_64. It provided SQLite 3.26.0-16.el8_6.4 to fix CVE-2026-11822 and CVE-2026-11824.
Red Hat issued Important advisory RHSA-2026:58939 for specified RHEL 8.8 update-service and extended-life-cycle channels. The update addressed both SQLite FTS5 flaws with version 3.26.0-18.el8_8.3 packages.
Red Hat issued Important advisory RHSA-2026:58938 for standard RHEL 8 and RHEL 8.10 Extended Life Cycle deployments. The advisory fixed CVE-2026-11822 and CVE-2026-11824 with SQLite 3.26.0-21.el8_10 packages.
Red Hat issued Important advisory RHSA-2026:58936 for RHEL 9 to remediate the two SQLite FTS5 vulnerabilities. The update provided SQLite version 3.34.1-11.el9_8 across supported RHEL 9 architectures and product variants.
Red Hat issued Important advisory RHSA-2026:58927 for RHEL 10, addressing CVE-2026-11822 and CVE-2026-11824. It supplied SQLite 3.46.1-6.el10_2 for supported x86_64, s390x, ppc64le, and aarch64 product variants.
CVE-2026-11822, which permits arbitrary code execution through crafted SQLite FTS5 data, and CVE-2026-11824, an FTS5 heap-based buffer overflow that can enable code execution or crashes, were published.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
19 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.