Source: mongo-c-driver Version: 2.5.3-1 Severity: important Tags: security upstream Forwarded: https://jira.mongodb.org/browse/CDRIVER-6417 X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for mongo-c-driver. CVE-2026-93393[0]: | A heap-based buffer overflow exists in the TLS transport layer of | the MongoDB C Driver when built with the Windows platform TLS | backend. A remote endpoint that the client connects to can cause the | driver to write uncontrolled data outside the bounds of a heap | allocation while processing incoming encrypted traffic after the TLS | handshake completes. No authentication or user interaction is | required, because the affected processing occurs before any | application-level authentication completes. Triggering this issue | may lead to memory corruption in the client process, disclosure of | adjacent heap memory, or termination of the process. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-93393 https://www.cve.org/CVERecord?id=CVE-2026-93393 [1] https://jira.mongodb.org/browse/CDRIVER-6417 Please adjust the affected versions in the BTS as needed. Regards, Salvatore

