[CLSA-2026:1787677972] Fix of 9 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-25 17:13:11 UTC
Description:
* SECURITY UPDATE: memory exposure or denial of service through malformed document diffs - debian/patches/CVE-2026-9753.patch: validate document-diff array bounds and BSONColumn values applied by $_internalApplyOplogUpdate - CVE-2026-9753 * SECURITY UPDATE: denial of service through MaxKey exchange ranges - debian/patches/CVE-2026-9749.patch: route MaxKey values to the final consumer instead of triggering an invariant failure - CVE-2026-9749 * SECURITY UPDATE: denial of service through strict-winding polygons in geometry collections - debian/patches/CVE-2026-9752.patch: guard geometry collection operations against strict-winding polygons without S2 regions - CVE-2026-9752 * SECURITY UPDATE: denial of service through nested BSONColumn values - debian/patches/CVE-2026-9740.patch: reject BSONColumn values nested inside other BSONColumn data during validation - CVE-2026-9740 * SECURITY UPDATE: crashes or incorrect results from metadata field collisions - debian/patches/CVE-2026-9750.patch: safely load internal metadata and strip colliding user fields during cross-shard serialization - CVE-2026-9750
Updated packages:
  • mongodb5_5.0.31-1+tuxcare.els15_amd64.deb
    sha:4ec0034c7c62ddd0d1a9167af654719b6e4d9a96
  • mongodb5-mongos_5.0.31-1+tuxcare.els15_amd64.deb
    sha:c3c254d7fa5a8d10a4d8ec97d0c5163459a750f4
  • mongodb5-server_5.0.31-1+tuxcare.els15_amd64.deb
    sha:43f9d06dd013ddb5cbde1042082c6822076b4308
  • mongodb5-shell_5.0.31-1+tuxcare.els15_amd64.deb
    sha:21ac2bd4c81a5874989aad4b4353a19df43d4db6
  • mongodb5_5.0.31-1+tuxcare.els15_arm64.deb
    sha:6e4df13160c2e089e339447dd1724b32f95db883
  • mongodb5-mongos_5.0.31-1+tuxcare.els15_arm64.deb
    sha:5b12c5f006e3060b27103703070cd796336d4ad1
  • mongodb5-server_5.0.31-1+tuxcare.els15_arm64.deb
    sha:076a5dbdd9bffce55e5a737f3002b33a2ca29b05
  • mongodb5-shell_5.0.31-1+tuxcare.els15_arm64.deb
    sha:d9d1df1bdda355e2e9eadc1cf7543763a69920b4
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.