Release date:
2026-08-25 17:01:49 UTC
Description:
* SECURITY UPDATE: Information disclosure through uninitialized filemd5
state
- debian/patches/CVE-2026-4147.patch: zero-initialize MD5 state before
returning partial filemd5 results
- CVE-2026-4147
* SECURITY UPDATE: Use-after-free while converting BSON objects to
JavaScript arrays
- debian/patches/CVE-2026-11933.patch: retain an owned BSON object while
constructing the JavaScript array
- CVE-2026-11933
* SECURITY UPDATE: Denial of service through strict-winding polygons in a
GeometryCollection
- debian/patches/CVE-2026-9752.patch: reject strict-winding polygons
nested in GeometryCollections before 2dsphere processing
- CVE-2026-9752
* SECURITY UPDATE: Authorization bypass through the internal $mergeCursors
aggregation stage
- debian/patches/CVE-2025-6713.patch: require the cluster internal
privilege when parsing $mergeCursors
- CVE-2025-6713
Updated packages:
-
mongodb44_4.4.29-1+tuxcare.els15_amd64.deb
sha:a6b2cdcc61f42d14fabdc47b18fdcbf6dadff7bf
-
mongodb44-mongos_4.4.29-1+tuxcare.els15_amd64.deb
sha:3d6d7d2a3bec85149084e7112588ca13ee8decd3
-
mongodb44-server_4.4.29-1+tuxcare.els15_amd64.deb
sha:06c7fd3649597ff3c7d79a313e06b921e9659a01
-
mongodb44-shell_4.4.29-1+tuxcare.els15_amd64.deb
sha:4b42d71992a4c05cd065d0634ae17070ea841b9e
-
mongodb44_4.4.29-1+tuxcare.els15_arm64.deb
sha:db68a1178fbed39feac1038323d1333321117bf7
-
mongodb44-mongos_4.4.29-1+tuxcare.els15_arm64.deb
sha:d2cf8f5992d919c26c39ccb3aaf9501ea8a8e3d9
-
mongodb44-server_4.4.29-1+tuxcare.els15_arm64.deb
sha:12def5fe7f90321d13904513a19855fd39e66383
-
mongodb44-shell_4.4.29-1+tuxcare.els15_arm64.deb
sha:7c19ff3d279dd233eef4c9e22b8e122c1e6bed79
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.