Hi Roberto, On Fri, Sep 18, 2026 at 09:11:20PM -0400, Roberto C. Sánchez wrote: > Hi Salvatore, > > On Fri, Sep 18, 2026 at 08:53:06PM +0200, Salvatore Bonaccorso wrote: > > CVE-2026-93393[0]: > > | A heap-based buffer overflow exists in the TLS transport layer of > > | the MongoDB C Driver when built with the Windows platform TLS > > | backend. A remote endpoint that the client connects to can cause the > > Note that this vulnerability only exists when mongo-c-driver is built > with components that are only available on Windows. Based on that, I > would recommend that this vulnerability be triaged as <unimportant>. (I > don't think that we have support for a does-not-affect-debian-binary > state yet.) > > The fix will be included in the next unstable upload (either 2.5.5 or > 2.6.0, I forget which is coming next). But it is not worth the > effort/risk to backport the fix to trixie and bookworm.
Ah right, thanks for for reporting back! Regards, Salvatore

