[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2026-84969/mongo-c-driver: bookworm not-affected

Sylvain Beucler (@beuc) gitlab at salsa.debian.org
Tue Sep 15 09:59:56 BST 2026



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
9edec734 by Sylvain Beucler at 2026-09-15T10:21:20+02:00
CVE-2026-84969/mongo-c-driver: bookworm not-affected

trixie probably neither.

'mcommon_string_append_base64_encode' introduced in referenced commit with vulnerable (patched) code.

- - - - -
9923fe64 by Sylvain Beucler at 2026-09-15T10:21:20+02:00
lts: add mongo-c-driver

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -13247,9 +13247,11 @@ CVE-2026-84970 (A numeric truncation weakness exists in the JSON parsing compone
 CVE-2026-84969 (A memory-handling error in the BSON-to-JSON conversion helpers of the  ...)
 	- mongo-c-driver 2.5.2-1
 	[trixie] - mongo-c-driver <no-dsa> (Minor issue)
+	[bookworm] - mongo-c-driver <not-affected> (Vulnerable code introduced later)
 	NOTE: https://jira.mongodb.org/browse/CDRIVER-6410
 	NOTE: Fixed by: https://github.com/mongodb/mongo-c-driver/commit/4229afa3bb4d0842edd5ee8da0f5143bd563e0bd (2.5.2)
 	NOTE: Fixed by: https://github.com/mongodb/mongo-c-driver/commit/08d0cfaaf08a54d7e87a5e5fa8d38251bf0eeca6 (1.30.9)
+	NOTE: Introduced by: https://github.com/mongodb/mongo-c-driver/commit/f2c1bb7989177fa2ddba1a915e8423e46ee1defe (1.30.0)
 CVE-2026-84968 (An out-of-bounds read in the BSON decoding component of the MongoDB PH ...)
 	- php-mongodb <unfixed>
 	[trixie] - php-mongodb <no-dsa> (Minor issue)


=====================================
data/dla-needed.txt
=====================================
@@ -387,6 +387,11 @@ memcached (Abhijith PA)
 mistral
   NOTE: 20260612: Added by Front-Desk (rouca)
 --
+mongo-c-driver
+  NOTE: 20260915: Added by Front-Desk (Beuc)
+  NOTE: 20260915: Follow trixie 13.7 (1 CVEs)
+  NOTE: 20260915: Also fix newer (medium) CVEs (Beuc/front-desk)
+--
 nagios4
   NOTE: 20260904: Added by Front-Desk (pochu)
 --



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/b5e7d592c0abcce13e7776cf5974c49272dae095...9923fe6427380e4c222bf088986289867e47a51e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/b5e7d592c0abcce13e7776cf5974c49272dae095...9923fe6427380e4c222bf088986289867e47a51e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260915/63f5eab2/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list