Source: mongo-c-driver
Version: 2.3.0-1
Severity: important
Tags: security upstream
Forwarded: https://jira.mongodb.org/browse/CDRIVER-6281
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Control: found -1 1.30.4-1+deb13u2

Hi,

The following vulnerability was published for mongo-c-driver.

CVE-2026-9100[0]:
| The MongoDB C Driver's legacy GridFS API accepts malformed file
| metadata from the database without adequate validation. Crafted
| documents in a GridFS collection may cause any application that
| reads those files via the legacy API to either crash (via a
| division-by-zero) or silently leak process memory contents (via an
| out-of-bounds read).


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-9100
    https://www.cve.org/CVERecord?id=CVE-2026-9100
[1] https://jira.mongodb.org/browse/CDRIVER-6281

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to