[CLSA-2026:1790938298] Fix CVE(s): CVE-2026-8053
Type:
security
Severity:
Important
Release date:
2026-10-02 10:52:02 UTC
Description:
* SECURITY UPDATE: Denial of service through a malformed stapled OCSP response during an outbound TLS handshake - debian/patches/CVE-2026-13070.patch: reject an OCSP response that cannot be decoded before attempting certificate-status validation - CVE-2026-13070 * SECURITY UPDATE: Authorization bypass through duplicate fields in a $graphLookup stage - debian/patches/CVE-2026-13060.patch: reject duplicate fields while parsing $graphLookup to keep authorization and execution namespaces consistent - CVE-2026-13060 * SECURITY UPDATE: Out-of-bounds memory access through malformed document diffs supplied to $_internalApplyOplogUpdate - debian/patches/CVE-2026-9753.patch: validate document-diff array bounds and BSONColumn data while applying external oplog updates - CVE-2026-9753 * SECURITY UPDATE: Server crash when a GeoJSON GeometryCollection contains a strict-winding Polygon - debian/patches/CVE-2026-9752.patch: detect strict-winding polygons in geometry collections before projection or 2dsphere indexing - CVE-2026-9752
CVEs fixed:
Updated packages:
  • mongodb6_6.0.26-1+tuxcare.els17_amd64.deb
    sha:9965858aecf2c54ff8f4611d649809443c3579e0
  • mongodb6-mongos_6.0.26-1+tuxcare.els17_amd64.deb
    sha:c7ea52080de3e8c3e1fc6d1d187cd61816999e94
  • mongodb6-server_6.0.26-1+tuxcare.els17_amd64.deb
    sha:c7eda60b27a037074a93068340317a71fcc76218
  • mongodb6-shell_6.0.26-1+tuxcare.els17_amd64.deb
    sha:c8ec2035832547c69660c7ca69f6e340eecf7725
  • mongodb6_6.0.26-1+tuxcare.els17_arm64.deb
    sha:1a3daf13d7b1ae0612abda1c2d54af23d55340a3
  • mongodb6-mongos_6.0.26-1+tuxcare.els17_arm64.deb
    sha:b001f2f133628fbadd9c462b505c4d5611caf9f2
  • mongodb6-server_6.0.26-1+tuxcare.els17_arm64.deb
    sha:2431cb65d407ac5c0b2b5e2184b2401f5e809573
  • mongodb6-shell_6.0.26-1+tuxcare.els17_arm64.deb
    sha:1f83abdf73d01718647ebacd033d18905c8cede6
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.