[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2026-84969/mongo-c-driver: bookworm not-affected
Sylvain Beucler (@beuc)
gitlab at salsa.debian.org
Tue Sep 15 09:59:56 BST 2026
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker
Commits:
9edec734 by Sylvain Beucler at 2026-09-15T10:21:20+02:00
CVE-2026-84969/mongo-c-driver: bookworm not-affected
trixie probably neither.
'mcommon_string_append_base64_encode' introduced in referenced commit with vulnerable (patched) code.
- - - - -
9923fe64 by Sylvain Beucler at 2026-09-15T10:21:20+02:00
lts: add mongo-c-driver
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -13247,9 +13247,11 @@ CVE-2026-84970 (A numeric truncation weakness exists in the JSON parsing compone
CVE-2026-84969 (A memory-handling error in the BSON-to-JSON conversion helpers of the ...)
- mongo-c-driver 2.5.2-1
[trixie] - mongo-c-driver <no-dsa> (Minor issue)
+ [bookworm] - mongo-c-driver <not-affected> (Vulnerable code introduced later)
NOTE: https://jira.mongodb.org/browse/CDRIVER-6410
NOTE: Fixed by: https://github.com/mongodb/mongo-c-driver/commit/4229afa3bb4d0842edd5ee8da0f5143bd563e0bd (2.5.2)
NOTE: Fixed by: https://github.com/mongodb/mongo-c-driver/commit/08d0cfaaf08a54d7e87a5e5fa8d38251bf0eeca6 (1.30.9)
+ NOTE: Introduced by: https://github.com/mongodb/mongo-c-driver/commit/f2c1bb7989177fa2ddba1a915e8423e46ee1defe (1.30.0)
CVE-2026-84968 (An out-of-bounds read in the BSON decoding component of the MongoDB PH ...)
- php-mongodb <unfixed>
[trixie] - php-mongodb <no-dsa> (Minor issue)
=====================================
data/dla-needed.txt
=====================================
@@ -387,6 +387,11 @@ memcached (Abhijith PA)
mistral
NOTE: 20260612: Added by Front-Desk (rouca)
--
+mongo-c-driver
+ NOTE: 20260915: Added by Front-Desk (Beuc)
+ NOTE: 20260915: Follow trixie 13.7 (1 CVEs)
+ NOTE: 20260915: Also fix newer (medium) CVEs (Beuc/front-desk)
+--
nagios4
NOTE: 20260904: Added by Front-Desk (pochu)
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/b5e7d592c0abcce13e7776cf5974c49272dae095...9923fe6427380e4c222bf088986289867e47a51e
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/b5e7d592c0abcce13e7776cf5974c49272dae095...9923fe6427380e4c222bf088986289867e47a51e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260915/63f5eab2/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list