[CLSA-2026:1787727747] Fix of 9 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-26 07:03:12 UTC
Description:
* SECURITY UPDATE: memory exposure or denial of service through malformed document diffs - debian/patches/CVE-2026-9753.patch: validate document-diff array bounds and BSONColumn values applied by $_internalApplyOplogUpdate - CVE-2026-9753 * SECURITY UPDATE: denial of service through MaxKey exchange ranges - debian/patches/CVE-2026-9749.patch: route MaxKey values to the final consumer instead of triggering an invariant failure - CVE-2026-9749 * SECURITY UPDATE: denial of service through strict-winding polygons in geometry collections - debian/patches/CVE-2026-9752.patch: guard geometry collection operations against strict-winding polygons without S2 regions - CVE-2026-9752 * SECURITY UPDATE: denial of service through nested BSONColumn values - debian/patches/CVE-2026-9740.patch: reject BSONColumn values nested inside other BSONColumn data during validation - CVE-2026-9740 * SECURITY UPDATE: crashes or incorrect results from metadata field collisions - debian/patches/CVE-2026-9750.patch: safely load internal metadata and strip colliding user fields during cross-shard serialization - CVE-2026-9750
Updated packages:
  • mongodb5_5.0.31-1+tuxcare.els15_amd64.deb
    sha:4ec0034c7c62ddd0d1a9167af654719b6e4d9a96
  • mongodb5-mongos_5.0.31-1+tuxcare.els15_amd64.deb
    sha:5aa392cc47a3ff1eba8cfc90bb00fca8555334bb
  • mongodb5-server_5.0.31-1+tuxcare.els15_amd64.deb
    sha:8dacff9d5ea5a7721c6ae34dbcd4ca57728f5d58
  • mongodb5-shell_5.0.31-1+tuxcare.els15_amd64.deb
    sha:20cce5c01afa701727e6e2ab5b3472bcd4a8983b
  • mongodb5_5.0.31-1+tuxcare.els15_arm64.deb
    sha:6e4df13160c2e089e339447dd1724b32f95db883
  • mongodb5-mongos_5.0.31-1+tuxcare.els15_arm64.deb
    sha:d38c657e56cb1000b802f14998090f2f07421018
  • mongodb5-server_5.0.31-1+tuxcare.els15_arm64.deb
    sha:fe0e99ed3134979bb0a47077c222fdcec9be9fe2
  • mongodb5-shell_5.0.31-1+tuxcare.els15_arm64.deb
    sha:ae84f500d0263a9d9a719502b92af57ea11cab35
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.