Data Security

Bogus SQLite vulnerabilities highlight flaws in CVE pipeline

Source PC website developer. Real software development code. JavaScript code in text editor. Computer interface. Abstract technology background. Java Software engineer concept.

The Register reports that a batch of critical and high-rated SQLite CVEs, which were recently added to the National Vulnerability Database (NVD) with enrichment from CISA, were identified as technically invalid by security researchers. This incident exposes significant weaknesses in the current CVE (Common Vulnerabilities and Exposures) pipeline.

Software supply chain security firm JFrog reported that six purported SQLite vulnerabilities, published on a new GitHub repository, were entirely fabricated. Analysis suggested these advisories were likely AI-generated, and JFrog's testing confirmed that none of the reported vulnerabilities could be reproduced. One alleged use-after-free vulnerability, initially assigned a CVSS score of 10.0 by Red Hat, was based on a non-existent function in the affected SQLite version. The other 49 CVEs in the repository, claiming to affect libraw and ESP32-audioI2S, were also found to be fake, with one exception containing a real bug mislabeled with unverified metadata. MITRE has since rejected the entire batch of advisories. This situation underscores a systemic issue where automated vulnerability ingestion lacks a mandatory checkpoint for independent reproduction. The NVD's backlog, exacerbated by a surge in submissions and operational challenges, has reduced its ability to manually review and enrich CVE records, allowing plausible-sounding but fake advisories to enter the system. This can lead to wasted time for security professionals chasing non-existent threats. JFrog recommends verifying vendor corroboration, checking for commit hashes or pull requests, and examining code references for legitimacy before acting on new CVEs.

Source: The Register

You can skip this ad in 5 seconds