Hi Roberto,

On Fri, Sep 18, 2026 at 09:11:20PM -0400, Roberto C. Sánchez wrote:
> Hi Salvatore,
> 
> On Fri, Sep 18, 2026 at 08:53:06PM +0200, Salvatore Bonaccorso wrote:
> > CVE-2026-93393[0]:
> > | A heap-based buffer overflow exists in the TLS transport layer of
> > | the MongoDB C Driver when built with the Windows platform TLS
> > | backend. A remote endpoint that the client connects to can cause the
> 
> Note that this vulnerability only exists when mongo-c-driver is built
> with components that are only available on Windows. Based on that, I
> would recommend that this vulnerability be triaged as <unimportant>. (I
> don't think that we have support for a does-not-affect-debian-binary
> state yet.)
> 
> The fix will be included in the next unstable upload (either 2.5.5 or
> 2.6.0, I forget which is coming next). But it is not worth the
> effort/risk to backport the fix to trixie and bookworm.

Ah right, thanks for for reporting back!

Regards,
Salvatore

Reply via email to