Release date:
2026-10-02 11:04:18 UTC
Description:
* SECURITY UPDATE: Denial of service through a malformed stapled OCSP
response during an outbound TLS handshake
- debian/patches/CVE-2026-13070.patch: reject an OCSP response that cannot
be decoded before attempting certificate-status validation
- CVE-2026-13070
* SECURITY UPDATE: Authorization bypass through duplicate fields in a
$graphLookup stage
- debian/patches/CVE-2026-13060.patch: reject duplicate fields while
parsing $graphLookup to keep authorization and execution namespaces
consistent
- CVE-2026-13060
* SECURITY UPDATE: Out-of-bounds memory access through malformed document
diffs supplied to $_internalApplyOplogUpdate
- debian/patches/CVE-2026-9753.patch: validate document-diff array bounds
and BSONColumn data while applying external oplog updates
- CVE-2026-9753
* SECURITY UPDATE: Server crash when a GeoJSON GeometryCollection contains
a strict-winding Polygon
- debian/patches/CVE-2026-9752.patch: detect strict-winding polygons in
geometry collections before projection or 2dsphere indexing
- CVE-2026-9752
Updated packages:
-
mongodb6_6.0.26-1+tuxcare.els17_amd64.deb
sha:9965858aecf2c54ff8f4611d649809443c3579e0
-
mongodb6-mongos_6.0.26-1+tuxcare.els17_amd64.deb
sha:c2d5f7ed528d7061106887c70b1eebbaee38ecf2
-
mongodb6-server_6.0.26-1+tuxcare.els17_amd64.deb
sha:812a5cabe21403b0603e6cf8786e83f4b3987b89
-
mongodb6-shell_6.0.26-1+tuxcare.els17_amd64.deb
sha:661f1e91be31393588d7da5b4b5771da74ae571b
-
mongodb6_6.0.26-1+tuxcare.els17_arm64.deb
sha:1a3daf13d7b1ae0612abda1c2d54af23d55340a3
-
mongodb6-mongos_6.0.26-1+tuxcare.els17_arm64.deb
sha:884bd572033cede8950e97f06712951570d468ff
-
mongodb6-server_6.0.26-1+tuxcare.els17_arm64.deb
sha:a1144a918e6e9354bff54538c85594239c3f51c3
-
mongodb6-shell_6.0.26-1+tuxcare.els17_arm64.deb
sha:aaab8fd48c5023ad1140069c6f051deef9caa5d5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.