[CLSA-2026:1776079135] Fix CVE(s): CVE-2025-3085
Type:
security
Severity:
Critical
Release date:
2026-04-13 11:18:59 UTC
Description:
* SECURITY UPDATE: CRL validation only checked leaf certificate - debian/patches/CVE-2025-3085.patch: add X509_V_FLAG_CRL_CHECK_ALL flag in _setupCRL() to validate entire certificate chain against CRL, not just the leaf certificate. Simplify CRL import log message. - CVE-2025-3085
Updated packages:
  • mongodb42_4.2.25-1+tuxcare.els4_amd64.deb
    sha:106c909b2c4efc09dd44e9925d53248872bbf343
  • mongodb42-mongos_4.2.25-1+tuxcare.els4_amd64.deb
    sha:9c3b0cdc21e909d6aeedfc56264928bd63eb83d7
  • mongodb42-server_4.2.25-1+tuxcare.els4_amd64.deb
    sha:81d66f0f0278917229169f1b8974114466b59a41
  • mongodb42-shell_4.2.25-1+tuxcare.els4_amd64.deb
    sha:670db3d1da8c8aa4c6ebaeda9fece5de8de3af7c
  • mongodb42_4.2.25-1+tuxcare.els4_arm64.deb
    sha:fce703f86271ede96d21cd5619f68aa83cb36b99
  • mongodb42-mongos_4.2.25-1+tuxcare.els4_arm64.deb
    sha:f3d68df7c50d197c5ac835a7ee3cd89faf85cb89
  • mongodb42-server_4.2.25-1+tuxcare.els4_arm64.deb
    sha:bd36af2a76cd48caf4934f825fa0d9530d544157
  • mongodb42-shell_4.2.25-1+tuxcare.els4_arm64.deb
    sha:bc831f23f5475c8d219159a169c49864bb9c8c63
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.