Release date:
2026-08-26 07:03:12 UTC
Description:
* SECURITY UPDATE: memory exposure or denial of service through malformed
document diffs
- debian/patches/CVE-2026-9753.patch: validate document-diff array bounds
and BSONColumn values applied by $_internalApplyOplogUpdate
- CVE-2026-9753
* SECURITY UPDATE: denial of service through MaxKey exchange ranges
- debian/patches/CVE-2026-9749.patch: route MaxKey values to the final
consumer instead of triggering an invariant failure
- CVE-2026-9749
* SECURITY UPDATE: denial of service through strict-winding polygons in
geometry collections
- debian/patches/CVE-2026-9752.patch: guard geometry collection operations
against strict-winding polygons without S2 regions
- CVE-2026-9752
* SECURITY UPDATE: denial of service through nested BSONColumn values
- debian/patches/CVE-2026-9740.patch: reject BSONColumn values nested inside
other BSONColumn data during validation
- CVE-2026-9740
* SECURITY UPDATE: crashes or incorrect results from metadata field collisions
- debian/patches/CVE-2026-9750.patch: safely load internal metadata and strip
colliding user fields during cross-shard serialization
- CVE-2026-9750
Updated packages:
-
mongodb5_5.0.31-1+tuxcare.els15_amd64.deb
sha:4ec0034c7c62ddd0d1a9167af654719b6e4d9a96
-
mongodb5-mongos_5.0.31-1+tuxcare.els15_amd64.deb
sha:5aa392cc47a3ff1eba8cfc90bb00fca8555334bb
-
mongodb5-server_5.0.31-1+tuxcare.els15_amd64.deb
sha:8dacff9d5ea5a7721c6ae34dbcd4ca57728f5d58
-
mongodb5-shell_5.0.31-1+tuxcare.els15_amd64.deb
sha:20cce5c01afa701727e6e2ab5b3472bcd4a8983b
-
mongodb5_5.0.31-1+tuxcare.els15_arm64.deb
sha:6e4df13160c2e089e339447dd1724b32f95db883
-
mongodb5-mongos_5.0.31-1+tuxcare.els15_arm64.deb
sha:d38c657e56cb1000b802f14998090f2f07421018
-
mongodb5-server_5.0.31-1+tuxcare.els15_arm64.deb
sha:fe0e99ed3134979bb0a47077c222fdcec9be9fe2
-
mongodb5-shell_5.0.31-1+tuxcare.els15_arm64.deb
sha:ae84f500d0263a9d9a719502b92af57ea11cab35
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.