[CLSA-2026:1775054057] Fix CVE(s): CVE-2025-3085
Type:
security
Severity:
Critical
Release date:
2026-04-01 14:34:20 UTC
Description:
* SECURITY UPDATE: Intermediate certificate revocation not checked with CRL - debian/patches/CVE-2025-3085.patch: add X509_V_FLAG_CRL_CHECK_ALL flag so OpenSSL validates the entire certificate chain against the CRL, not only the leaf certificate - CVE-2025-3085
Updated packages:
  • mongodb44_4.4.29-1+tuxcare.els3_amd64.deb
    sha:97ea571647edc88f0be25a33a82d531ddccc8842
  • mongodb44-mongos_4.4.29-1+tuxcare.els3_amd64.deb
    sha:a1166a1b25a3fa8d07a8c6d412666aa27361b65f
  • mongodb44-server_4.4.29-1+tuxcare.els3_amd64.deb
    sha:dae8d47bde290e12814dd62dc8862fa116554298
  • mongodb44-shell_4.4.29-1+tuxcare.els3_amd64.deb
    sha:dee3981c56cd760e406abdbede604a80c986c3d9
  • mongodb44_4.4.29-1+tuxcare.els3_arm64.deb
    sha:a95687946cba27dcfd55e9ccacc6f2482454abd7
  • mongodb44-mongos_4.4.29-1+tuxcare.els3_arm64.deb
    sha:985fdba34ab5a309ef7320a95cc71124cec47c22
  • mongodb44-server_4.4.29-1+tuxcare.els3_arm64.deb
    sha:56b4aa2710948ea6621d266a7a4465a4cead988f
  • mongodb44-shell_4.4.29-1+tuxcare.els3_arm64.deb
    sha:b2143a0c3dfadae6c17f37c65feb2c3edd72a8af
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.