[CLSA-2026:1788513518] Fix CVE(s): CVE-2026-9749
Type:
security
Severity:
Moderate
Release date:
2026-09-11 15:35:19 UTC
Description:
* SECURITY UPDATE: Denial of service through MaxKey values in a key-range $exchange stage - debian/patches/CVE-2026-9749.patch: route MaxKey field values to the last exchange consumer bucket instead of triggering an invariant - CVE-2026-9749
CVEs fixed:
Updated packages:
  • mongodb44_4.4.29-1+tuxcare.els16_amd64.deb
    sha:d53fc4ae5dfdaefe5779ce8f73325dd7e5725266
  • mongodb44-mongos_4.4.29-1+tuxcare.els16_amd64.deb
    sha:fbb1137183ac43c477a0fdafb641612346ad41ea
  • mongodb44-server_4.4.29-1+tuxcare.els16_amd64.deb
    sha:69f16b29412f8577529680380b184b80f8374892
  • mongodb44-shell_4.4.29-1+tuxcare.els16_amd64.deb
    sha:f09488653f3902c2090bc0ee615099b331c2f367
  • mongodb44_4.4.29-1+tuxcare.els16_arm64.deb
    sha:0322168d7246b04d57772e4e2f9c75f8ddf058b5
  • mongodb44-mongos_4.4.29-1+tuxcare.els16_arm64.deb
    sha:ee17f96c9b6ca61188dbfc582cacc837e8f4b2ed
  • mongodb44-server_4.4.29-1+tuxcare.els16_arm64.deb
    sha:357e5e1007501679bf9f71adea5a34c954704795
  • mongodb44-shell_4.4.29-1+tuxcare.els16_arm64.deb
    sha:150c489ba50140f84011d3b3054d9e923bdd40c4
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.