[CLSA-2026:1790939029] Fix CVE(s): CVE-2026-8053
Type:
security
Severity:
Important
Release date:
2026-10-02 11:04:18 UTC
Description:
* SECURITY UPDATE: Denial of service through a malformed stapled OCSP response during an outbound TLS handshake - debian/patches/CVE-2026-13070.patch: reject an OCSP response that cannot be decoded before attempting certificate-status validation - CVE-2026-13070 * SECURITY UPDATE: Authorization bypass through duplicate fields in a $graphLookup stage - debian/patches/CVE-2026-13060.patch: reject duplicate fields while parsing $graphLookup to keep authorization and execution namespaces consistent - CVE-2026-13060 * SECURITY UPDATE: Out-of-bounds memory access through malformed document diffs supplied to $_internalApplyOplogUpdate - debian/patches/CVE-2026-9753.patch: validate document-diff array bounds and BSONColumn data while applying external oplog updates - CVE-2026-9753 * SECURITY UPDATE: Server crash when a GeoJSON GeometryCollection contains a strict-winding Polygon - debian/patches/CVE-2026-9752.patch: detect strict-winding polygons in geometry collections before projection or 2dsphere indexing - CVE-2026-9752
CVEs fixed:
Updated packages:
  • mongodb6_6.0.26-1+tuxcare.els17_amd64.deb
    sha:9965858aecf2c54ff8f4611d649809443c3579e0
  • mongodb6-mongos_6.0.26-1+tuxcare.els17_amd64.deb
    sha:c2d5f7ed528d7061106887c70b1eebbaee38ecf2
  • mongodb6-server_6.0.26-1+tuxcare.els17_amd64.deb
    sha:812a5cabe21403b0603e6cf8786e83f4b3987b89
  • mongodb6-shell_6.0.26-1+tuxcare.els17_amd64.deb
    sha:661f1e91be31393588d7da5b4b5771da74ae571b
  • mongodb6_6.0.26-1+tuxcare.els17_arm64.deb
    sha:1a3daf13d7b1ae0612abda1c2d54af23d55340a3
  • mongodb6-mongos_6.0.26-1+tuxcare.els17_arm64.deb
    sha:884bd572033cede8950e97f06712951570d468ff
  • mongodb6-server_6.0.26-1+tuxcare.els17_arm64.deb
    sha:a1144a918e6e9354bff54538c85594239c3f51c3
  • mongodb6-shell_6.0.26-1+tuxcare.els17_arm64.deb
    sha:aaab8fd48c5023ad1140069c6f051deef9caa5d5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.