Your message dated Mon, 14 Sep 2026 16:49:24 +0000
with message-id <[email protected]>
and subject line Bug#1147409: fixed in ruby-mongo 2.26.0-1
has caused the Debian Bug report #1147409,
regarding ruby-mongo: CVE-2026-88030
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1147409: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1147409
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: ruby-mongo
Version: 2.25.0-1
Severity: important
Tags: security upstream
Forwarded: https://jira.mongodb.org/browse/RUBY-3941
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for ruby-mongo.
CVE-2026-88030[0]:
| Improper neutralization of special elements in data query logic in
| the GridFS component of the MongoDB Ruby Driver can cause a caller-
| supplied structured file identifier to be interpreted as a query
| condition rather than as a literal identifier. An authenticated user
| who can influence the identifier passed by an affected application
| may obtain stored file content beyond the intended target or cause
| all GridFS file chunks in the affected bucket to be removed,
| rendering stored file content unreadable.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-88030
https://www.cve.org/CVERecord?id=CVE-2026-88030
[1] https://jira.mongodb.org/browse/RUBY-3941
[2]
https://github.com/mongodb/mongo-ruby-driver/commit/ed62bb56c2e24c79113709331862d0aa3da74c6d
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: ruby-mongo
Source-Version: 2.26.0-1
Done: Simon Quigley <[email protected]>
We believe that the bug you reported is fixed in the latest version of
ruby-mongo, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Simon Quigley <[email protected]> (supplier of updated ruby-mongo package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Mon, 14 Sep 2026 11:30:07 -0500
Source: ruby-mongo
Architecture: source
Version: 2.26.0-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Ruby Team
<[email protected]>
Changed-By: Simon Quigley <[email protected]>
Closes: 1147409
Changes:
ruby-mongo (2.26.0-1) unstable; urgency=medium
.
* Team upload.
* New upstream release (Closes: #1147409).
- Fixes CVE-2026-88030.
Checksums-Sha1:
82ee8d051fc09a721ea11bcc6fc9f68efa654774 2034 ruby-mongo_2.26.0-1.dsc
86f7f3add5981a9a856e0cea06ffa4e0cb32b974 1650824 ruby-mongo_2.26.0.orig.tar.gz
8a5c4e67b272c870ec4e06e83b5f3926e6caeba9 2864 ruby-mongo_2.26.0-1.debian.tar.xz
e02f5b3300750a8ea1e7dabcdb99a7710554bde5 7401
ruby-mongo_2.26.0-1_source.buildinfo
Checksums-Sha256:
485ebcf4cb139776ba49ae9942b4d444fa08697f370117464f8e5852fec920c2 2034
ruby-mongo_2.26.0-1.dsc
68754d4e5914bad806200041b96b250732f09f8cc13655f636e4639d10382f14 1650824
ruby-mongo_2.26.0.orig.tar.gz
03e8e7a5466152a59a11c82af9c6776a01228db1d15839fdbf91d2562d73378a 2864
ruby-mongo_2.26.0-1.debian.tar.xz
9bd6e536d4ecec709b5fa2387888642079ba8854d7c1e26b5268adf0fad41473 7401
ruby-mongo_2.26.0-1_source.buildinfo
Files:
126ec36be7d5c903c5534eefd7134215 2034 ruby optional ruby-mongo_2.26.0-1.dsc
781275464ad4f49b6c7cce38f8d0d8cc 1650824 ruby optional
ruby-mongo_2.26.0.orig.tar.gz
4cb84cadf1ef4e38491bf21989d39459 2864 ruby optional
ruby-mongo_2.26.0-1.debian.tar.xz
16bad3e452b6d238701169fba2b813d0 7401 ruby optional
ruby-mongo_2.26.0-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEXHq+og+GMEWcyMi14n8s+EWML6QFAmqoITIACgkQ4n8s+EWM
L6S0NA/+MWDmZW4AyAPgnQhUWYuovH/Z4YmsndY3Mq7DGgXXieZOM2tuUJxCLmcJ
5HTmnnCEt/PGrJ0Mrh1FbNu8FV2KYjw6TNy8avisvo3FbQ8f37yAYi64fz/JxOFS
/wgNXYBsk5BC2ZMr1zMKXZccJ7fXvqgQ3F4d4s0xohz01chjpNbvRDXnOZrn4SpM
IrtBVRQce7GrZz14965TPrYunc3xsSJKdcqgs1zmyhrjBcAv68epZSKHKnHYfrd3
66GxrcYkIU9aIB5Z1Z0/kSHmYg7ncgYY2ugznc1NzEQg7XZNqdw0RjFGxt2XgoZF
PPbxzR+V211uuNnmsAamznSfVLs3HfyW/Df7Iwowb3CYInvmF/G4bYYtrkh5rLn0
QReHdaN21doUMVb9H0POomzSHfR/auGW90/WtN6/7XVCK7w/d6MmyYjqFts/nRxW
gEKEohKHaiA5sOmyPGXRPhMKwA5vbk7I5OglXxlfESxj7uiA86RHY+qGNG/8UakV
gMVBCeTsck0xHxrRhfl94EL2i5m9/WdoseJZyqGRdIn5FDxp+0CHOQMKcJM3Vsf/
Tlst5M1/nVvlq+39uO5KW8kfI8dK9rhUQjiLxiDk26OnQTMn1Orbq/kOAoZKIx9g
FNOMa3becLCs/u16/9QxN1rsx8tyMxnPYExCRKhG5qt5leDydyU=
=OASi
-----END PGP SIGNATURE-----
pgpWZhGPO0qlo.pgp
Description: PGP signature
--- End Message ---