[CLSA-2026:1789130782] Fix CVE(s): CVE-2026-13061, CVE-2026-13066, CVE-2026-9749, CVE-2026-9752
Type:
security
Severity:
Moderate
Release date:
2026-09-11 12:46:37 UTC
Description:
* SECURITY UPDATE: unauthorized access to session metadata through $listSessions - debian/patches/CVE-2026-13061.patch: require the internal cluster privilege when $_internalPredicate is supplied to $listSessions - CVE-2026-13061 * SECURITY UPDATE: process memory disclosure through DBPointer BSON serialization - debian/patches/CVE-2026-13066.patch: make DBPointer state immutable and validate the JavaScript class before reading ObjectId private data - CVE-2026-13066 * SECURITY UPDATE: server crash when $exchange key-range routing receives MaxKey - debian/patches/CVE-2026-9749.patch: route MaxKey documents to the final consumer bucket instead of triggering an invariant failure - CVE-2026-9749 * SECURITY UPDATE: null-pointer dereference from strict-winding polygons in GeoJSON GeometryCollection values - debian/patches/CVE-2026-9752.patch: detect strict-winding polygons inside geometry collections before 2dsphere indexing or projection - CVE-2026-9752
Updated packages:
  • mongodb42_4.2.25-1+tuxcare.els17_amd64.deb
    sha:cd294d1b262ee39b8549f57c740a53c557ab6510
  • mongodb42-mongos_4.2.25-1+tuxcare.els17_amd64.deb
    sha:95f00686bd9159ef0388b76b9c9b0b49812b63e6
  • mongodb42-server_4.2.25-1+tuxcare.els17_amd64.deb
    sha:25a01e05c52f35c79f4c1f0defb9069bf509ebda
  • mongodb42-shell_4.2.25-1+tuxcare.els17_amd64.deb
    sha:22aac3deed8d9e13b7e69e8bb04dab00be17ff09
  • mongodb42_4.2.25-1+tuxcare.els17_arm64.deb
    sha:43ef2acd4a1225aebb50cf8b7cf7ee30c836fc50
  • mongodb42-mongos_4.2.25-1+tuxcare.els17_arm64.deb
    sha:a2bea87eb7d7fa23dba703b1311e0d900f501378
  • mongodb42-server_4.2.25-1+tuxcare.els17_arm64.deb
    sha:b6dbcee8a9c9f6812205cdcb630a2ee4638cce9e
  • mongodb42-shell_4.2.25-1+tuxcare.els17_arm64.deb
    sha:144a1e7430f959981dfbbd57b04d99b01b3925d9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.