Release date:
2026-09-11 12:38:52 UTC
Description:
* SECURITY UPDATE: unauthorized access to session metadata through
$listSessions
- debian/patches/CVE-2026-13061.patch: require the internal cluster
privilege when $_internalPredicate is supplied to $listSessions
- CVE-2026-13061
* SECURITY UPDATE: process memory disclosure through DBPointer BSON
serialization
- debian/patches/CVE-2026-13066.patch: make DBPointer state immutable and
validate the JavaScript class before reading ObjectId private data
- CVE-2026-13066
* SECURITY UPDATE: server crash when $exchange key-range routing receives
MaxKey
- debian/patches/CVE-2026-9749.patch: route MaxKey documents to the final
consumer bucket instead of triggering an invariant failure
- CVE-2026-9749
* SECURITY UPDATE: null-pointer dereference from strict-winding polygons in
GeoJSON GeometryCollection values
- debian/patches/CVE-2026-9752.patch: detect strict-winding polygons inside
geometry collections before 2dsphere indexing or projection
- CVE-2026-9752
Updated packages:
-
mongodb42_4.2.25-1+tuxcare.els17_amd64.deb
sha:cd294d1b262ee39b8549f57c740a53c557ab6510
-
mongodb42-mongos_4.2.25-1+tuxcare.els17_amd64.deb
sha:4d975536daa34baf3862c00ffca286703061d1dd
-
mongodb42-server_4.2.25-1+tuxcare.els17_amd64.deb
sha:0fbfd199c639e6a2ec3a119a5652da884221435c
-
mongodb42-shell_4.2.25-1+tuxcare.els17_amd64.deb
sha:0769eba6bae9861a993a44803560a627f067237a
-
mongodb42_4.2.25-1+tuxcare.els17_arm64.deb
sha:43ef2acd4a1225aebb50cf8b7cf7ee30c836fc50
-
mongodb42-mongos_4.2.25-1+tuxcare.els17_arm64.deb
sha:8a9e8ce446014d64efed21886ca8520f4b50c82e
-
mongodb42-server_4.2.25-1+tuxcare.els17_arm64.deb
sha:bd261ee89e5570ac6836ecbbd9bc134cfaad4781
-
mongodb42-shell_4.2.25-1+tuxcare.els17_arm64.deb
sha:00def70ab8a452577622feb4853ab3c45c8b9e33
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.