Release date:
2026-10-02 10:52:02 UTC
Description:
* SECURITY UPDATE: Denial of service through a malformed stapled OCSP
response during an outbound TLS handshake
- debian/patches/CVE-2026-13070.patch: reject an OCSP response that cannot
be decoded before attempting certificate-status validation
- CVE-2026-13070
* SECURITY UPDATE: Authorization bypass through duplicate fields in a
$graphLookup stage
- debian/patches/CVE-2026-13060.patch: reject duplicate fields while
parsing $graphLookup to keep authorization and execution namespaces
consistent
- CVE-2026-13060
* SECURITY UPDATE: Out-of-bounds memory access through malformed document
diffs supplied to $_internalApplyOplogUpdate
- debian/patches/CVE-2026-9753.patch: validate document-diff array bounds
and BSONColumn data while applying external oplog updates
- CVE-2026-9753
* SECURITY UPDATE: Server crash when a GeoJSON GeometryCollection contains
a strict-winding Polygon
- debian/patches/CVE-2026-9752.patch: detect strict-winding polygons in
geometry collections before projection or 2dsphere indexing
- CVE-2026-9752
Updated packages:
-
mongodb6_6.0.26-1+tuxcare.els17_amd64.deb
sha:9965858aecf2c54ff8f4611d649809443c3579e0
-
mongodb6-mongos_6.0.26-1+tuxcare.els17_amd64.deb
sha:c7ea52080de3e8c3e1fc6d1d187cd61816999e94
-
mongodb6-server_6.0.26-1+tuxcare.els17_amd64.deb
sha:c7eda60b27a037074a93068340317a71fcc76218
-
mongodb6-shell_6.0.26-1+tuxcare.els17_amd64.deb
sha:c8ec2035832547c69660c7ca69f6e340eecf7725
-
mongodb6_6.0.26-1+tuxcare.els17_arm64.deb
sha:1a3daf13d7b1ae0612abda1c2d54af23d55340a3
-
mongodb6-mongos_6.0.26-1+tuxcare.els17_arm64.deb
sha:b001f2f133628fbadd9c462b505c4d5611caf9f2
-
mongodb6-server_6.0.26-1+tuxcare.els17_arm64.deb
sha:2431cb65d407ac5c0b2b5e2184b2401f5e809573
-
mongodb6-shell_6.0.26-1+tuxcare.els17_arm64.deb
sha:1f83abdf73d01718647ebacd033d18905c8cede6
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.