You have to wonder how much of this there is.
As someone who has been digging through the bottom of the barrel of MITRE CVE records & given they had been hallucinating references for years ( Look, ma, I'm a CVE reference - Link rot in CVE references, part 2 | blagh.nyanbinary.de ) I am very much unsurprised they also failed to validate reports…
Announcement of the non-issue on the SQLite Forum: SQLite User Forum: Fake CVEs against SQLite
It’s not explicit but it sounds like they weren’t informed ahead of time either? If so I am really wondering what role MITREs CNA sees themselves in - they do not validate the finding, they do not perform coordination, they “enrich” reporter input by making up some domains, and call it a day?
Edit: Ok, so, yeah, MITRE just didn’t tell SQLite before publication: SQLite User Forum: Fake CVEs against SQLite
Edit: Wrote up my digging as a blogpost: On those MITRE SQLite vulnerabilities | blagh.nyanbinary.de
/Edit
The github commits list an actual email address, associated with Wuhan University, 2023182210054@whu.edu.cn : https://github.com/programmervuln/cveadvisory-/commit/bfbf978edfac5579794e6ee128bd4c88f42324cd.patch
This email ID can be found associated with two papers on Researchgate, best I can tell (from the preview) with an Author of the papers:
Unfortunately I can’t actually tickle out of RG which author & I made the mistake of sending one (1) curl request to RG so I am now IP blocked, lmao, so I can’t even check the actual papers anymore if they are related.
Obvious salt: Git commit emails are spoofable, this is no proof that the owner of that address indeed made these commits.
Edit: Numero uno is absolutely related, see e.g. this excerpt from the abstract:
Furthermore, we deploy MLG-UAF to conduct large-scale security auditing on mainstream open-source software such as libtiff, LibRaw, SQLite, ImageMagick and Zephyr RTOS. In real-world industrial source code scanning, our framework successfully discovered 17 unique confirmed UAF vulnerabilities assigned with independent Common Vulnerabilities and Exposures (CVE) IDs (CVE-2026 series, RESERVED and not yet publicized), covering cross-functional kernel UAF, intra-procedural cache UAF, race-condition UAF and multimedia parsing UAF scenarios.Real CVE case studies on CVE-2026-51291 (SQLite JSON cache flaw) and CVE-2023-32233 (Linux netfilter kernel vulnerability) demonstrate that MLG-UAF can precisely capture the fixed free-then-use spatial topological fingerprint of UAF defects and accurately resolve ambiguous multi-level pointer aliasing, even under heavy control-flow obfuscation.
Edit: Reached out to the email address to get access to the preprint, received a response from a qq address for dr. jie/lloyd jie, which would match the primary author of the paper. Unfortunately didn’t receive the paper, “still being modified”, lol.