Release date:
2026-08-25 17:13:11 UTC
Description:
* SECURITY UPDATE: memory exposure or denial of service through malformed
document diffs
- debian/patches/CVE-2026-9753.patch: validate document-diff array bounds
and BSONColumn values applied by $_internalApplyOplogUpdate
- CVE-2026-9753
* SECURITY UPDATE: denial of service through MaxKey exchange ranges
- debian/patches/CVE-2026-9749.patch: route MaxKey values to the final
consumer instead of triggering an invariant failure
- CVE-2026-9749
* SECURITY UPDATE: denial of service through strict-winding polygons in
geometry collections
- debian/patches/CVE-2026-9752.patch: guard geometry collection operations
against strict-winding polygons without S2 regions
- CVE-2026-9752
* SECURITY UPDATE: denial of service through nested BSONColumn values
- debian/patches/CVE-2026-9740.patch: reject BSONColumn values nested inside
other BSONColumn data during validation
- CVE-2026-9740
* SECURITY UPDATE: crashes or incorrect results from metadata field collisions
- debian/patches/CVE-2026-9750.patch: safely load internal metadata and strip
colliding user fields during cross-shard serialization
- CVE-2026-9750
Updated packages:
-
mongodb5_5.0.31-1+tuxcare.els15_amd64.deb
sha:4ec0034c7c62ddd0d1a9167af654719b6e4d9a96
-
mongodb5-mongos_5.0.31-1+tuxcare.els15_amd64.deb
sha:c3c254d7fa5a8d10a4d8ec97d0c5163459a750f4
-
mongodb5-server_5.0.31-1+tuxcare.els15_amd64.deb
sha:43f9d06dd013ddb5cbde1042082c6822076b4308
-
mongodb5-shell_5.0.31-1+tuxcare.els15_amd64.deb
sha:21ac2bd4c81a5874989aad4b4353a19df43d4db6
-
mongodb5_5.0.31-1+tuxcare.els15_arm64.deb
sha:6e4df13160c2e089e339447dd1724b32f95db883
-
mongodb5-mongos_5.0.31-1+tuxcare.els15_arm64.deb
sha:5b12c5f006e3060b27103703070cd796336d4ad1
-
mongodb5-server_5.0.31-1+tuxcare.els15_arm64.deb
sha:076a5dbdd9bffce55e5a737f3002b33a2ca29b05
-
mongodb5-shell_5.0.31-1+tuxcare.els15_arm64.deb
sha:d9d1df1bdda355e2e9eadc1cf7543763a69920b4
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.