[CLSA-2026:1787677287] Fix of 12 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-25 17:01:49 UTC
Description:
* SECURITY UPDATE: Information disclosure through uninitialized filemd5 state - debian/patches/CVE-2026-4147.patch: zero-initialize MD5 state before returning partial filemd5 results - CVE-2026-4147 * SECURITY UPDATE: Use-after-free while converting BSON objects to JavaScript arrays - debian/patches/CVE-2026-11933.patch: retain an owned BSON object while constructing the JavaScript array - CVE-2026-11933 * SECURITY UPDATE: Denial of service through strict-winding polygons in a GeometryCollection - debian/patches/CVE-2026-9752.patch: reject strict-winding polygons nested in GeometryCollections before 2dsphere processing - CVE-2026-9752 * SECURITY UPDATE: Authorization bypass through the internal $mergeCursors aggregation stage - debian/patches/CVE-2025-6713.patch: require the cluster internal privilege when parsing $mergeCursors - CVE-2025-6713
Updated packages:
  • mongodb44_4.4.29-1+tuxcare.els15_amd64.deb
    sha:a6b2cdcc61f42d14fabdc47b18fdcbf6dadff7bf
  • mongodb44-mongos_4.4.29-1+tuxcare.els15_amd64.deb
    sha:3d6d7d2a3bec85149084e7112588ca13ee8decd3
  • mongodb44-server_4.4.29-1+tuxcare.els15_amd64.deb
    sha:06c7fd3649597ff3c7d79a313e06b921e9659a01
  • mongodb44-shell_4.4.29-1+tuxcare.els15_amd64.deb
    sha:4b42d71992a4c05cd065d0634ae17070ea841b9e
  • mongodb44_4.4.29-1+tuxcare.els15_arm64.deb
    sha:db68a1178fbed39feac1038323d1333321117bf7
  • mongodb44-mongos_4.4.29-1+tuxcare.els15_arm64.deb
    sha:d2cf8f5992d919c26c39ccb3aaf9501ea8a8e3d9
  • mongodb44-server_4.4.29-1+tuxcare.els15_arm64.deb
    sha:12def5fe7f90321d13904513a19855fd39e66383
  • mongodb44-shell_4.4.29-1+tuxcare.els15_arm64.deb
    sha:7c19ff3d279dd233eef4c9e22b8e122c1e6bed79
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.