[CLSA-2026:1787680417] Fix of 12 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-25 17:53:56 UTC
Description:
* SECURITY UPDATE: Information disclosure through uninitialized filemd5 state - debian/patches/CVE-2026-4147.patch: zero-initialize MD5 state before returning partial filemd5 results - CVE-2026-4147 * SECURITY UPDATE: Use-after-free while converting BSON objects to JavaScript arrays - debian/patches/CVE-2026-11933.patch: retain an owned BSON object while constructing the JavaScript array - CVE-2026-11933 * SECURITY UPDATE: Denial of service through strict-winding polygons in a GeometryCollection - debian/patches/CVE-2026-9752.patch: reject strict-winding polygons nested in GeometryCollections before 2dsphere processing - CVE-2026-9752 * SECURITY UPDATE: Authorization bypass through the internal $mergeCursors aggregation stage - debian/patches/CVE-2025-6713.patch: require the cluster internal privilege when parsing $mergeCursors - CVE-2025-6713
Updated packages:
  • mongodb44_4.4.29-1+tuxcare.els15_amd64.deb
    sha:a6b2cdcc61f42d14fabdc47b18fdcbf6dadff7bf
  • mongodb44-mongos_4.4.29-1+tuxcare.els15_amd64.deb
    sha:a2b8ec585aad50c050ca215468f029711fb1d166
  • mongodb44-server_4.4.29-1+tuxcare.els15_amd64.deb
    sha:7e27d276e338237628ba1d2de5be6751f14c04fd
  • mongodb44-shell_4.4.29-1+tuxcare.els15_amd64.deb
    sha:1417bb4cb512e13d7dad838ebbb07a3c06baa613
  • mongodb44_4.4.29-1+tuxcare.els15_arm64.deb
    sha:db68a1178fbed39feac1038323d1333321117bf7
  • mongodb44-mongos_4.4.29-1+tuxcare.els15_arm64.deb
    sha:38548df923d97d81e35df782626a9464458f680b
  • mongodb44-server_4.4.29-1+tuxcare.els15_arm64.deb
    sha:5567cf63cdccadc55285789c2a8cd05675bd310f
  • mongodb44-shell_4.4.29-1+tuxcare.els15_arm64.deb
    sha:4e9801d412e3d7f9e4ef5f1685eb6292c06ada51
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.