[CLSA-2026:1780310570] Fix CVE(s): CVE-2026-6914
Type:
security
Severity:
Important
Release date:
2026-06-01 10:43:03 UTC
Description:
* SECURITY UPDATE: Denial of service via MD5 checksum of malformed BSON object with deprecated ByteArray type - debian/patches/CVE-2026-6914.patch: Add ssize>=4 bounds check in binDataClean() for the ByteArrayDeprecated branch and guard md5_append() call with len>0 check in CmdFileMD5 - CVE-2026-6914
CVEs fixed:
Updated packages:
  • mongodb6_6.0.26-1+tuxcare.els8_amd64.deb
    sha:d337861c3428c1669da3729193c2a36b78e1bd3b
  • mongodb6-mongos_6.0.26-1+tuxcare.els8_amd64.deb
    sha:d01d555d32e7b3c9afd858592af8628b135822a0
  • mongodb6-server_6.0.26-1+tuxcare.els8_amd64.deb
    sha:f2f0af445dd7c184e42dad80d5160a8b6081f2fc
  • mongodb6-shell_6.0.26-1+tuxcare.els8_amd64.deb
    sha:6f3bdc2edc227b53abfc48cad5d4fb858307dee7
  • mongodb6_6.0.26-1+tuxcare.els8_arm64.deb
    sha:fa4e1a1f9abdec6f76e2f1c4c83058c1095fb0b5
  • mongodb6-mongos_6.0.26-1+tuxcare.els8_arm64.deb
    sha:9b625451df2a59e3e6480a773d6b420e2f9b9198
  • mongodb6-server_6.0.26-1+tuxcare.els8_arm64.deb
    sha:edabf4e59849de61850e6b820acf347dff0fcc71
  • mongodb6-shell_6.0.26-1+tuxcare.els8_arm64.deb
    sha:a46b7a0b3108c80844294812da03bd3b9637b1ab
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.