[CLSA-2026:1789130319] Fix CVE(s): CVE-2026-13061, CVE-2026-13066, CVE-2026-9749, CVE-2026-9752
Type:
security
Severity:
Moderate
Release date:
2026-09-11 12:38:52 UTC
Description:
* SECURITY UPDATE: unauthorized access to session metadata through $listSessions - debian/patches/CVE-2026-13061.patch: require the internal cluster privilege when $_internalPredicate is supplied to $listSessions - CVE-2026-13061 * SECURITY UPDATE: process memory disclosure through DBPointer BSON serialization - debian/patches/CVE-2026-13066.patch: make DBPointer state immutable and validate the JavaScript class before reading ObjectId private data - CVE-2026-13066 * SECURITY UPDATE: server crash when $exchange key-range routing receives MaxKey - debian/patches/CVE-2026-9749.patch: route MaxKey documents to the final consumer bucket instead of triggering an invariant failure - CVE-2026-9749 * SECURITY UPDATE: null-pointer dereference from strict-winding polygons in GeoJSON GeometryCollection values - debian/patches/CVE-2026-9752.patch: detect strict-winding polygons inside geometry collections before 2dsphere indexing or projection - CVE-2026-9752
Updated packages:
  • mongodb42_4.2.25-1+tuxcare.els17_amd64.deb
    sha:cd294d1b262ee39b8549f57c740a53c557ab6510
  • mongodb42-mongos_4.2.25-1+tuxcare.els17_amd64.deb
    sha:4d975536daa34baf3862c00ffca286703061d1dd
  • mongodb42-server_4.2.25-1+tuxcare.els17_amd64.deb
    sha:0fbfd199c639e6a2ec3a119a5652da884221435c
  • mongodb42-shell_4.2.25-1+tuxcare.els17_amd64.deb
    sha:0769eba6bae9861a993a44803560a627f067237a
  • mongodb42_4.2.25-1+tuxcare.els17_arm64.deb
    sha:43ef2acd4a1225aebb50cf8b7cf7ee30c836fc50
  • mongodb42-mongos_4.2.25-1+tuxcare.els17_arm64.deb
    sha:8a9e8ce446014d64efed21886ca8520f4b50c82e
  • mongodb42-server_4.2.25-1+tuxcare.els17_arm64.deb
    sha:bd261ee89e5570ac6836ecbbd9bc134cfaad4781
  • mongodb42-shell_4.2.25-1+tuxcare.els17_arm64.deb
    sha:00def70ab8a452577622feb4853ab3c45c8b9e33
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.