Hi Salvatore,

On Fri, Sep 18, 2026 at 08:53:06PM +0200, Salvatore Bonaccorso wrote:
> CVE-2026-93393[0]:
> | A heap-based buffer overflow exists in the TLS transport layer of
> | the MongoDB C Driver when built with the Windows platform TLS
> | backend. A remote endpoint that the client connects to can cause the

Note that this vulnerability only exists when mongo-c-driver is built
with components that are only available on Windows. Based on that, I
would recommend that this vulnerability be triaged as <unimportant>. (I
don't think that we have support for a does-not-affect-debian-binary
state yet.)

The fix will be included in the next unstable upload (either 2.5.5 or
2.6.0, I forget which is coming next). But it is not worth the
effort/risk to backport the fix to trixie and bookworm.

Regards,

-Roberto

-- 
Roberto C. Sánchez

Reply via email to