SQLite Critical CVEs or LLM Slop?
Over the past few days, a new GitHub repository published a series of SQLite vulnerability advisories, many of which were flagged as critical by the National Vulnerability Database (NVD) and the Cybersecurity and Infrastructure Security Agency (CISA). However, upon investigation by JFrog security researchers, many of these claims were found to be unfounded.
The advisories claimed various issues with SQLite, including heap use-after-free, improper memory management, and deleted pointers being accessed. However, these claims were found to be incorrect or fabricated. The security researchers conducted isolated testing on the reported vulnerabilities and discovered that the described scenarios either did not exist, were not exploitable, or were the result of fabricated code.
One vulnerability claimed a heap use-after-free in sqlite3ReleaseTempReg() but was debunked as impossible due to the function's design. Another claimed that ExprListDelete() fails to clear back-references, but the code review showed no such pointers existed. The vulnerability reports also claimed issues with jsonParseFree() and jsonRemoveFunc, but these were found to be unsupported functions in the target versions.
The researchers concluded that these CVEs were likely "LLM slop," or content generated by artificial intelligence, rather than genuine vulnerabilities. They warned that such fabricated advisories could lead organizations to waste time and resources investigating non-existent vulnerabilities and pollute vulnerability databases. The incident highlights the need for a more robust system for vulnerability reporting and verification to prevent the spread of false information.
Written by urgent.news from Lobsters's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
