Release date:
2026-06-22 19:56:54 UTC
Description:
* SECURITY UPDATE: nine CVE backports
- debian/patches/CVE-2025-6710.patch: bound JSON parser recursion depth
in src/mongo/bson/json.{cpp,h} (kMaxDepth=200) to prevent stack
overflow on deeply nested input.
- CVE-2025-6710
- debian/patches/CVE-2025-6711.patch: wrap user-supplied filter
payloads with redact() in find/distinct/getMore/aggregate/findAndModify
and query-plan logging to avoid leaking sensitive data through
diagnostic logs.
- CVE-2025-6711
- debian/patches/CVE-2025-6713.patch: register $mergeCursors as
REGISTER_INTERNAL_DOCUMENT_SOURCE so non-internal clients cannot
invoke the stage and bypass authorization.
- CVE-2025-6713
- debian/patches/CVE-2025-10059.patch: replace invariant with
tassert(100901) in ShardingTaskExecutor::scheduleRemoteCommandOnAny
to avoid mongos abort on lsid uid mismatch.
- CVE-2025-10059
- debian/patches/CVE-2025-10061.patch: introduce
assertMergingInputType helper (uassert 9961600) in five accumulators
to reject mismatched merging-pass input instead of crashing.
- CVE-2025-10061
- debian/patches/CVE-2025-13643.patch: tighten killCursors auth check
against TOCTOU race in commands/killcursors_cmd.cpp,
cursor_manager, and the mongos sibling path.
- CVE-2025-13643
- debian/patches/CVE-2025-14345.patch: guard apiParameters
preservation in TransactionParticipant::getAPIParameters() to
block cross-API-version prepared-txn smuggling.
- CVE-2025-14345
- debian/patches/CVE-2025-14847.patch: fix MessageCompressorZlib
to return the actual decompressed length (MongoBleed memory
disclosure via undersized output reuse).
- CVE-2025-14847
- debian/patches/CVE-2026-25609.patch: require the profile filter
parameter to be unset for the {profile:-1} auth shortcut in
ProfileCmdBase::checkAuthForCommand, closing a missing-auth gap
on profile filter installation.
- CVE-2026-25609
Updated packages:
-
mongodb5_5.0.31-1+tuxcare.els7_amd64.deb
sha:1feb4d6cc80a1669d9dd272b8e22f0aa7329ba06
-
mongodb5-mongos_5.0.31-1+tuxcare.els7_amd64.deb
sha:880fba2e385db7ff52876023d6a1ed62fe39b930
-
mongodb5-server_5.0.31-1+tuxcare.els7_amd64.deb
sha:cbf4954b347d73bd97fd1a9e728d7836659a6b76
-
mongodb5-shell_5.0.31-1+tuxcare.els7_amd64.deb
sha:d38a95f51d24803b6d948390f604d10c62fd21f7
-
mongodb5_5.0.31-1+tuxcare.els7_arm64.deb
sha:cbd3036527bb126c28a9cde97d7e6cb978b85b8a
-
mongodb5-mongos_5.0.31-1+tuxcare.els7_arm64.deb
sha:5095704a38ad48d69ccc4c2050701bb58150516e
-
mongodb5-server_5.0.31-1+tuxcare.els7_arm64.deb
sha:f07b76073063495845aa7a8b4cb1a32aa7cac5a4
-
mongodb5-shell_5.0.31-1+tuxcare.els7_arm64.deb
sha:4c65b8c2cbbf5438ead865ecffd369be8d051bcb
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.