Hi Salvatore, On Fri, Sep 18, 2026 at 08:53:06PM +0200, Salvatore Bonaccorso wrote: > CVE-2026-93393[0]: > | A heap-based buffer overflow exists in the TLS transport layer of > | the MongoDB C Driver when built with the Windows platform TLS > | backend. A remote endpoint that the client connects to can cause the
Note that this vulnerability only exists when mongo-c-driver is built with components that are only available on Windows. Based on that, I would recommend that this vulnerability be triaged as <unimportant>. (I don't think that we have support for a does-not-affect-debian-binary state yet.) The fix will be included in the next unstable upload (either 2.5.5 or 2.6.0, I forget which is coming next). But it is not worth the effort/risk to backport the fix to trixie and bookworm. Regards, -Roberto -- Roberto C. Sánchez

