{
  "document": {
    "aggregate_severity": {
      "text": "Critical"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/cloudlinux7els/vex/2025/cve-2025-3277-els_os-cloudlinux7els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-06-12T22:27:44Z",
      "generator": {
        "date": "2026-06-12T22:27:44Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2025-3277-ELS_OS-CLOUDLINUX7ELS",
      "initial_release_date": "2025-04-14T17:15:00Z",
      "revision_history": [
        {
          "date": "2025-04-14T17:15:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2025-11-29T10:36:36Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2025-12-23T22:15:38Z",
          "number": "3",
          "summary": "Update document"
        },
        {
          "date": "2026-06-12T22:27:44Z",
          "number": "4",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "4"
    },
    "title": "Security update on CVE-2025-3277"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "CloudLinux 7",
                "product": {
                  "name": "CloudLinux 7",
                  "product_id": "CloudLinux-7",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:cloudlinux:cloudlinux:7:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "CloudLinux"
          }
        ],
        "category": "vendor",
        "name": "Cloud Linux Software, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "lemon-0:3.7.17-8.el7_7.1.tuxcare.els2.x86_64",
                "product": {
                  "name": "lemon-0:3.7.17-8.el7_7.1.tuxcare.els2.x86_64",
                  "product_id": "lemon-0:3.7.17-8.el7_7.1.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/lemon@3.7.17-8.el7_7.1.tuxcare.els2?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "sqlite-0:3.7.17-8.el7_7.1.tuxcare.els2.x86_64",
                "product": {
                  "name": "sqlite-0:3.7.17-8.el7_7.1.tuxcare.els2.x86_64",
                  "product_id": "sqlite-0:3.7.17-8.el7_7.1.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/sqlite@3.7.17-8.el7_7.1.tuxcare.els2?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "sqlite-devel-0:3.7.17-8.el7_7.1.tuxcare.els2.x86_64",
                "product": {
                  "name": "sqlite-devel-0:3.7.17-8.el7_7.1.tuxcare.els2.x86_64",
                  "product_id": "sqlite-devel-0:3.7.17-8.el7_7.1.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/sqlite-devel@3.7.17-8.el7_7.1.tuxcare.els2?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "sqlite-tcl-0:3.7.17-8.el7_7.1.tuxcare.els2.x86_64",
                "product": {
                  "name": "sqlite-tcl-0:3.7.17-8.el7_7.1.tuxcare.els2.x86_64",
                  "product_id": "sqlite-tcl-0:3.7.17-8.el7_7.1.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/sqlite-tcl@3.7.17-8.el7_7.1.tuxcare.els2?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "sqlite-0:3.7.17-8.el7_7.1.tuxcare.els2.i686",
                "product": {
                  "name": "sqlite-0:3.7.17-8.el7_7.1.tuxcare.els2.i686",
                  "product_id": "sqlite-0:3.7.17-8.el7_7.1.tuxcare.els2.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/sqlite@3.7.17-8.el7_7.1.tuxcare.els2?arch=i686"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "sqlite-devel-0:3.7.17-8.el7_7.1.tuxcare.els2.i686",
                "product": {
                  "name": "sqlite-devel-0:3.7.17-8.el7_7.1.tuxcare.els2.i686",
                  "product_id": "sqlite-devel-0:3.7.17-8.el7_7.1.tuxcare.els2.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/sqlite-devel@3.7.17-8.el7_7.1.tuxcare.els2?arch=i686"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "i686"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "sqlite-doc-0:3.7.17-8.el7_7.1.tuxcare.els2.noarch",
                "product": {
                  "name": "sqlite-doc-0:3.7.17-8.el7_7.1.tuxcare.els2.noarch",
                  "product_id": "sqlite-doc-0:3.7.17-8.el7_7.1.tuxcare.els2.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/cloudlinux/sqlite-doc@3.7.17-8.el7_7.1.tuxcare.els2?arch=noarch"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "noarch"
          }
        ],
        "category": "vendor",
        "name": "CloudLinux"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "lemon-0:3.7.17-8.el7_7.1.tuxcare.els2.x86_64 as a component of CloudLinux 7",
          "product_id": "CloudLinux-7:lemon-0:3.7.17-8.el7_7.1.tuxcare.els2.x86_64"
        },
        "product_reference": "lemon-0:3.7.17-8.el7_7.1.tuxcare.els2.x86_64",
        "relates_to_product_reference": "CloudLinux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "sqlite-0:3.7.17-8.el7_7.1.tuxcare.els2.i686 as a component of CloudLinux 7",
          "product_id": "CloudLinux-7:sqlite-0:3.7.17-8.el7_7.1.tuxcare.els2.i686"
        },
        "product_reference": "sqlite-0:3.7.17-8.el7_7.1.tuxcare.els2.i686",
        "relates_to_product_reference": "CloudLinux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "sqlite-0:3.7.17-8.el7_7.1.tuxcare.els2.x86_64 as a component of CloudLinux 7",
          "product_id": "CloudLinux-7:sqlite-0:3.7.17-8.el7_7.1.tuxcare.els2.x86_64"
        },
        "product_reference": "sqlite-0:3.7.17-8.el7_7.1.tuxcare.els2.x86_64",
        "relates_to_product_reference": "CloudLinux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "sqlite-devel-0:3.7.17-8.el7_7.1.tuxcare.els2.i686 as a component of CloudLinux 7",
          "product_id": "CloudLinux-7:sqlite-devel-0:3.7.17-8.el7_7.1.tuxcare.els2.i686"
        },
        "product_reference": "sqlite-devel-0:3.7.17-8.el7_7.1.tuxcare.els2.i686",
        "relates_to_product_reference": "CloudLinux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "sqlite-devel-0:3.7.17-8.el7_7.1.tuxcare.els2.x86_64 as a component of CloudLinux 7",
          "product_id": "CloudLinux-7:sqlite-devel-0:3.7.17-8.el7_7.1.tuxcare.els2.x86_64"
        },
        "product_reference": "sqlite-devel-0:3.7.17-8.el7_7.1.tuxcare.els2.x86_64",
        "relates_to_product_reference": "CloudLinux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "sqlite-doc-0:3.7.17-8.el7_7.1.tuxcare.els2.noarch as a component of CloudLinux 7",
          "product_id": "CloudLinux-7:sqlite-doc-0:3.7.17-8.el7_7.1.tuxcare.els2.noarch"
        },
        "product_reference": "sqlite-doc-0:3.7.17-8.el7_7.1.tuxcare.els2.noarch",
        "relates_to_product_reference": "CloudLinux-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "sqlite-tcl-0:3.7.17-8.el7_7.1.tuxcare.els2.x86_64 as a component of CloudLinux 7",
          "product_id": "CloudLinux-7:sqlite-tcl-0:3.7.17-8.el7_7.1.tuxcare.els2.x86_64"
        },
        "product_reference": "sqlite-tcl-0:3.7.17-8.el7_7.1.tuxcare.els2.x86_64",
        "relates_to_product_reference": "CloudLinux-7"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2025-3277",
      "cwe": {
        "id": "CWE-122",
        "name": "Heap-based Buffer Overflow"
      },
      "notes": [
        {
          "category": "description",
          "text": "An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer, it uses the original, untruncated size and thus a wild Heap Buffer overflow of size ~4GB can be triggered. This can result in arbitrary code execution.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        },
        {
          "category": "other",
          "text": "TuxCare has assessed that this vulnerability does not impact any currently supported TuxCare products. This evaluation may change as new information becomes available. For additional details regarding this vulnerability and affected products, refer to the provided references.",
          "title": "Statement"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "CloudLinux-7:lemon-0:3.7.17-8.el7_7.1.tuxcare.els2.x86_64",
          "CloudLinux-7:sqlite-0:3.7.17-8.el7_7.1.tuxcare.els2.i686",
          "CloudLinux-7:sqlite-0:3.7.17-8.el7_7.1.tuxcare.els2.x86_64",
          "CloudLinux-7:sqlite-devel-0:3.7.17-8.el7_7.1.tuxcare.els2.i686",
          "CloudLinux-7:sqlite-devel-0:3.7.17-8.el7_7.1.tuxcare.els2.x86_64",
          "CloudLinux-7:sqlite-doc-0:3.7.17-8.el7_7.1.tuxcare.els2.noarch",
          "CloudLinux-7:sqlite-tcl-0:3.7.17-8.el7_7.1.tuxcare.els2.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2025-3277"
        },
        {
          "category": "external",
          "summary": "https://sqlite.org/src/info/498e3f1cf57f164f",
          "url": "https://sqlite.org/src/info/498e3f1cf57f164f"
        }
      ],
      "release_date": "2025-04-14T17:15:00Z",
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CloudLinux-7:lemon-0:3.7.17-8.el7_7.1.tuxcare.els2.x86_64",
            "CloudLinux-7:sqlite-0:3.7.17-8.el7_7.1.tuxcare.els2.i686",
            "CloudLinux-7:sqlite-0:3.7.17-8.el7_7.1.tuxcare.els2.x86_64",
            "CloudLinux-7:sqlite-devel-0:3.7.17-8.el7_7.1.tuxcare.els2.i686",
            "CloudLinux-7:sqlite-devel-0:3.7.17-8.el7_7.1.tuxcare.els2.x86_64",
            "CloudLinux-7:sqlite-doc-0:3.7.17-8.el7_7.1.tuxcare.els2.noarch",
            "CloudLinux-7:sqlite-tcl-0:3.7.17-8.el7_7.1.tuxcare.els2.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        },
        {
          "category": "impact",
          "date": "2026-06-12T13:03:12.418800Z",
          "details": "Not vulnerable — CVE-2025-3277 targets an integer overflow in SQLite’s concat_ws() built‑in, which was introduced in 3.44.0; SQLite 3.7.17 predates this and does not include concat_ws at all. A review of the 3.7.17 source (func.c and related files) shows no concat_ws/concat implementation or matching buffer-allocation code paths—only unrelated nSep handling in tooling—so the trigger condition cannot occur. Because the affected function is absent, this version is outside the vulnerable scope.",
          "product_ids": [
            "CloudLinux-7:lemon-0:3.7.17-8.el7_7.1.tuxcare.els2.x86_64",
            "CloudLinux-7:sqlite-0:3.7.17-8.el7_7.1.tuxcare.els2.i686",
            "CloudLinux-7:sqlite-0:3.7.17-8.el7_7.1.tuxcare.els2.x86_64",
            "CloudLinux-7:sqlite-devel-0:3.7.17-8.el7_7.1.tuxcare.els2.i686",
            "CloudLinux-7:sqlite-devel-0:3.7.17-8.el7_7.1.tuxcare.els2.x86_64",
            "CloudLinux-7:sqlite-doc-0:3.7.17-8.el7_7.1.tuxcare.els2.noarch",
            "CloudLinux-7:sqlite-tcl-0:3.7.17-8.el7_7.1.tuxcare.els2.x86_64"
          ]
        }
      ]
    }
  ]
}