[CLSA-2026:1780500688] Fix CVE(s): CVE-2026-6914
Type:
security
Severity:
Important
Release date:
2026-06-03 15:31:40 UTC
Description:
* SECURITY UPDATE: DoS via malformed BSON MD5 checksum computation - debian/patches/CVE-2026-6914.patch: fix binDataClean() bounds check for ByteArrayDeprecated type and guard md5_append against zero-length data - CVE-2026-6914
CVEs fixed:
Updated packages:
  • mongodb42_4.2.25-1+tuxcare.els11_amd64.deb
    sha:b96d2abb7502476851344732bc67e43d301c5dd0
  • mongodb42-mongos_4.2.25-1+tuxcare.els11_amd64.deb
    sha:bc41e6a74b9a24e7ba9150c85215f55256d94159
  • mongodb42-server_4.2.25-1+tuxcare.els11_amd64.deb
    sha:50d4f9d028b332bd442be297fce9d81b5de73d6b
  • mongodb42-shell_4.2.25-1+tuxcare.els11_amd64.deb
    sha:3da33afa0c63ca65b89f1d051f3f9423df97680e
  • mongodb42_4.2.25-1+tuxcare.els11_arm64.deb
    sha:c045196b1a89c7b4655ac127aa79f3d15aa843d7
  • mongodb42-mongos_4.2.25-1+tuxcare.els11_arm64.deb
    sha:e186ea9e7fe21584ad24fe86c47d9067796f6910
  • mongodb42-server_4.2.25-1+tuxcare.els11_arm64.deb
    sha:cbab92649831e2b92a5a02af739b5580901b7fe8
  • mongodb42-shell_4.2.25-1+tuxcare.els11_arm64.deb
    sha:f73be41ccc7279099d683ad194ad3dcbd359e358
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.