Source: mongo-c-driver
Version: 2.5.3-1
Severity: important
Tags: security upstream
Forwarded: https://jira.mongodb.org/browse/CDRIVER-6417
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for mongo-c-driver.

CVE-2026-93393[0]:
| A heap-based buffer overflow exists in the TLS transport layer of
| the MongoDB C Driver when built with the Windows platform TLS
| backend. A remote endpoint that the client connects to can cause the
| driver to write uncontrolled data outside the bounds of a heap
| allocation while processing incoming encrypted traffic after the TLS
| handshake completes. No authentication or user interaction is
| required, because the affected processing occurs before any
| application-level authentication completes. Triggering this issue
| may lead to memory corruption in the client process, disclosure of
| adjacent heap memory, or termination of the process.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-93393
    https://www.cve.org/CVERecord?id=CVE-2026-93393
[1] https://jira.mongodb.org/browse/CDRIVER-6417

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to