[CLSA-2026:1782158749] Fix of 7 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-06-22 20:06:13 UTC
Description:
* SECURITY UPDATE: nine CVE backports - debian/patches/CVE-2025-6710.patch: bound JSON parser recursion depth in src/mongo/bson/json.{cpp,h} (kMaxDepth=200) to prevent stack overflow on deeply nested input. - CVE-2025-6710 - debian/patches/CVE-2025-6711.patch: wrap user-supplied filter payloads with redact() in find/distinct/getMore/aggregate/findAndModify and query-plan logging to avoid leaking sensitive data through diagnostic logs. - CVE-2025-6711 - debian/patches/CVE-2025-6713.patch: register $mergeCursors as REGISTER_INTERNAL_DOCUMENT_SOURCE so non-internal clients cannot invoke the stage and bypass authorization. - CVE-2025-6713 - debian/patches/CVE-2025-10059.patch: replace invariant with tassert(100901) in ShardingTaskExecutor::scheduleRemoteCommandOnAny to avoid mongos abort on lsid uid mismatch. - CVE-2025-10059 - debian/patches/CVE-2025-10061.patch: introduce assertMergingInputType helper (uassert 9961600) in five accumulators to reject mismatched merging-pass input instead of crashing. - CVE-2025-10061 - debian/patches/CVE-2025-13643.patch: tighten killCursors auth check against TOCTOU race in commands/killcursors_cmd.cpp, cursor_manager, and the mongos sibling path. - CVE-2025-13643 - debian/patches/CVE-2025-14345.patch: guard apiParameters preservation in TransactionParticipant::getAPIParameters() to block cross-API-version prepared-txn smuggling. - CVE-2025-14345 - debian/patches/CVE-2025-14847.patch: fix MessageCompressorZlib to return the actual decompressed length (MongoBleed memory disclosure via undersized output reuse). - CVE-2025-14847 - debian/patches/CVE-2026-25609.patch: require the profile filter parameter to be unset for the {profile:-1} auth shortcut in ProfileCmdBase::checkAuthForCommand, closing a missing-auth gap on profile filter installation. - CVE-2026-25609
Updated packages:
  • mongodb5_5.0.31-1+tuxcare.els7_amd64.deb
    sha:1feb4d6cc80a1669d9dd272b8e22f0aa7329ba06
  • mongodb5-mongos_5.0.31-1+tuxcare.els7_amd64.deb
    sha:74394c39554d80ff62623298a523f9350c2824d2
  • mongodb5-server_5.0.31-1+tuxcare.els7_amd64.deb
    sha:fbbf0c7bb8c76b718ab086088953bdc0b6e8113d
  • mongodb5-shell_5.0.31-1+tuxcare.els7_amd64.deb
    sha:bb1175ae37d896a3ae1dd765b6d4c90e4152a74e
  • mongodb5_5.0.31-1+tuxcare.els7_arm64.deb
    sha:cbd3036527bb126c28a9cde97d7e6cb978b85b8a
  • mongodb5-mongos_5.0.31-1+tuxcare.els7_arm64.deb
    sha:47b84ecc9d8d41b9fcb11e47e4173783d0cc128c
  • mongodb5-server_5.0.31-1+tuxcare.els7_arm64.deb
    sha:3b2ddf30cf93de8ad7b2c441f2b8ab179782dd15
  • mongodb5-shell_5.0.31-1+tuxcare.els7_arm64.deb
    sha:1ace9b716bc992c482810dd85d2a4c6cd49e8812
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.