[CLSA-2026:1776598170] Fix CVE(s): CVE-2026-1849
Type:
security
Severity:
Important
Release date:
2026-04-19 11:29:34 UTC
Description:
* SECURITY UPDATE: Uncontrolled recursion in ExpressionReduce::evaluate() - debian/patches/CVE-2026-1849.patch: add Value::depth() method and periodic depth check in the $reduce accumulation loop to throw Overflow error when accumulated value exceeds maximum allowable BSON depth - CVE-2026-1849
Updated packages:
  • mongodb44_4.4.29-1+tuxcare.els6_amd64.deb
    sha:1751e3274527984ca8a1f88545fbfe27284db8a1
  • mongodb44-mongos_4.4.29-1+tuxcare.els6_amd64.deb
    sha:c74f01b7aeb17a12e29e89578582ec70bf65db7f
  • mongodb44-server_4.4.29-1+tuxcare.els6_amd64.deb
    sha:9307f1a4a0e301daf7821d588785876fdcf555a7
  • mongodb44-shell_4.4.29-1+tuxcare.els6_amd64.deb
    sha:5460a27ff2361b386a762ff30fedf54b4b623b29
  • mongodb44_4.4.29-1+tuxcare.els6_arm64.deb
    sha:098e2b3a0b5fb6a2448bf4d8856aed5dd5e78a55
  • mongodb44-mongos_4.4.29-1+tuxcare.els6_arm64.deb
    sha:f90a5e33efbc0226b2267d50fd0c3c088a1518ee
  • mongodb44-server_4.4.29-1+tuxcare.els6_arm64.deb
    sha:92dc06c353804543a311639d5959d59668a00a9c
  • mongodb44-shell_4.4.29-1+tuxcare.els6_arm64.deb
    sha:ea40d153988a7e504136ce60db812851f69e5d0e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.