[CLSA-2026:1782158192] Fix of 7 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-06-22 19:56:54 UTC
Description:
* SECURITY UPDATE: nine CVE backports - debian/patches/CVE-2025-6710.patch: bound JSON parser recursion depth in src/mongo/bson/json.{cpp,h} (kMaxDepth=200) to prevent stack overflow on deeply nested input. - CVE-2025-6710 - debian/patches/CVE-2025-6711.patch: wrap user-supplied filter payloads with redact() in find/distinct/getMore/aggregate/findAndModify and query-plan logging to avoid leaking sensitive data through diagnostic logs. - CVE-2025-6711 - debian/patches/CVE-2025-6713.patch: register $mergeCursors as REGISTER_INTERNAL_DOCUMENT_SOURCE so non-internal clients cannot invoke the stage and bypass authorization. - CVE-2025-6713 - debian/patches/CVE-2025-10059.patch: replace invariant with tassert(100901) in ShardingTaskExecutor::scheduleRemoteCommandOnAny to avoid mongos abort on lsid uid mismatch. - CVE-2025-10059 - debian/patches/CVE-2025-10061.patch: introduce assertMergingInputType helper (uassert 9961600) in five accumulators to reject mismatched merging-pass input instead of crashing. - CVE-2025-10061 - debian/patches/CVE-2025-13643.patch: tighten killCursors auth check against TOCTOU race in commands/killcursors_cmd.cpp, cursor_manager, and the mongos sibling path. - CVE-2025-13643 - debian/patches/CVE-2025-14345.patch: guard apiParameters preservation in TransactionParticipant::getAPIParameters() to block cross-API-version prepared-txn smuggling. - CVE-2025-14345 - debian/patches/CVE-2025-14847.patch: fix MessageCompressorZlib to return the actual decompressed length (MongoBleed memory disclosure via undersized output reuse). - CVE-2025-14847 - debian/patches/CVE-2026-25609.patch: require the profile filter parameter to be unset for the {profile:-1} auth shortcut in ProfileCmdBase::checkAuthForCommand, closing a missing-auth gap on profile filter installation. - CVE-2026-25609
Updated packages:
  • mongodb5_5.0.31-1+tuxcare.els7_amd64.deb
    sha:1feb4d6cc80a1669d9dd272b8e22f0aa7329ba06
  • mongodb5-mongos_5.0.31-1+tuxcare.els7_amd64.deb
    sha:880fba2e385db7ff52876023d6a1ed62fe39b930
  • mongodb5-server_5.0.31-1+tuxcare.els7_amd64.deb
    sha:cbf4954b347d73bd97fd1a9e728d7836659a6b76
  • mongodb5-shell_5.0.31-1+tuxcare.els7_amd64.deb
    sha:d38a95f51d24803b6d948390f604d10c62fd21f7
  • mongodb5_5.0.31-1+tuxcare.els7_arm64.deb
    sha:cbd3036527bb126c28a9cde97d7e6cb978b85b8a
  • mongodb5-mongos_5.0.31-1+tuxcare.els7_arm64.deb
    sha:5095704a38ad48d69ccc4c2050701bb58150516e
  • mongodb5-server_5.0.31-1+tuxcare.els7_arm64.deb
    sha:f07b76073063495845aa7a8b4cb1a32aa7cac5a4
  • mongodb5-shell_5.0.31-1+tuxcare.els7_arm64.deb
    sha:4c65b8c2cbbf5438ead865ecffd369be8d051bcb
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.