[CLSA-2026:1787823214] Fix CVE(s): CVE-2025-13643, CVE-2026-9740, CVE-2026-9750, CVE-2026-9751
Type:
security
Severity:
Important
Release date:
2026-08-27 09:33:46 UTC
Description:
* SECURITY UPDATE: Authorization bypass through collisions between user fields and system metadata - debian/patches/CVE-2026-9750.patch: keep user-supplied metadata field names separate from system-injected document metadata - CVE-2026-9750 * SECURITY UPDATE: Denial of service through nested BSONColumn values - debian/patches/CVE-2026-9740.patch: reject BSONColumn values nested in literal or interleaved BSONColumn content - CVE-2026-9740 * SECURITY UPDATE: Sensitive server parameter values exposed in logs - debian/patches/CVE-2026-9751.patch: force redaction of parameters marked sensitive in setParameter log messages - CVE-2026-9751 * SECURITY UPDATE: Authorization bypass through a race in killCursors - debian/patches/CVE-2025-13643.patch: recheck cursor ownership while holding the cursor manager lock before killing a cursor - CVE-2025-13643
Updated packages:
  • mongodb6_6.0.26-1+tuxcare.els18_amd64.deb
    sha:bbf464e064b50a7e5fa58cb7c061cb7a7f6095b0
  • mongodb6-mongos_6.0.26-1+tuxcare.els18_amd64.deb
    sha:21f9b5759cbc668a095594a678722e0ae811e007
  • mongodb6-server_6.0.26-1+tuxcare.els18_amd64.deb
    sha:c54afe9dc855bf502084271272238c37fe830d8f
  • mongodb6-shell_6.0.26-1+tuxcare.els18_amd64.deb
    sha:4f8dd7dffe79231c211b2bd245191c351e93cf16
  • mongodb6_6.0.26-1+tuxcare.els18_arm64.deb
    sha:3d07f7d5d068f33a713b7dfa9762d4a295174520
  • mongodb6-mongos_6.0.26-1+tuxcare.els18_arm64.deb
    sha:108125d74fec45069276476ef830d18b6d450ebf
  • mongodb6-server_6.0.26-1+tuxcare.els18_arm64.deb
    sha:3ef678a1f0232ab5563925b67ad29dece1f4c684
  • mongodb6-shell_6.0.26-1+tuxcare.els18_arm64.deb
    sha:d38d33f49a0e8af64811d13d8187d538cdf0d950
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.