CVE-2026-39113: Sqlite Malloc Int64 Truncation

A 64-bit integer from sqlite3_value_int64() is passed to sqlite3_malloc(), which only accepts a 32-bit int. Integer truncation can result in an undersized buffer allocation leading to heap buffer overflow. Use sqlite3_malloc64() instead.

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0C
greprules fetch cve-2026-39113-sqlite-malloc-int64-truncation --engine opengrep

Description

A 64-bit integer from sqlite3_value_int64() is passed to sqlite3_malloc(), which only accepts a 32-bit int. Integer truncation can result in an undersized buffer allocation leading to heap buffer overflow. Use sqlite3_malloc64() instead.