[CLSA-2026:1784644826] Fix CVE(s): CVE-2026-1847
Type:
security
Severity:
Important
Release date:
2026-07-21 14:40:55 UTC
Description:
* SECURITY UPDATE: wire-message-size DoS via oversized OpMsg body reads - debian/patches/CVE-2026-1847.patch: introduce a slightly higher BSONObj size limit for wire messages (SERVER-113532); adds BSONObjMaxWireMessageSize and BSONObj::WireMessageSizeTrait in src/mongo/bson/{bsonobj.{cpp,h},util/builder.h}, threads the trait through src/mongo/db/commands/getmore_cmd.cpp, and validates op_msg body sections via a new WireMessagePayload type in src/mongo/rpc/{op_msg.cpp,object_check.h,wire_message_payload.h} with accompanying data_type_wire_message_payload_test.cpp coverage. - CVE-2026-1847
CVEs fixed:
Updated packages:
  • mongodb5_5.0.31-1+tuxcare.els13_amd64.deb
    sha:7729eb9e98e3f41fc380eb7568f4be669326523c
  • mongodb5-mongos_5.0.31-1+tuxcare.els13_amd64.deb
    sha:e78f375b4406750272ca10ec5b4249e0464bf081
  • mongodb5-server_5.0.31-1+tuxcare.els13_amd64.deb
    sha:b77848b5f5839a3eb4d2f3ee379bc37338c604f5
  • mongodb5-shell_5.0.31-1+tuxcare.els13_amd64.deb
    sha:5cc22094670a603513dda94be70e8e8809794310
  • mongodb5_5.0.31-1+tuxcare.els13_arm64.deb
    sha:be7e0e2fa379e312a9aeada4ff387a3988f9fbf3
  • mongodb5-mongos_5.0.31-1+tuxcare.els13_arm64.deb
    sha:8dedc24297ef3c32cc2fdf84659c3f3ff5edbaa0
  • mongodb5-server_5.0.31-1+tuxcare.els13_arm64.deb
    sha:6c195f01257d322a7123b39fc3148d163f224165
  • mongodb5-shell_5.0.31-1+tuxcare.els13_arm64.deb
    sha:fd9ecf62b338cab43ee0bb6827a716f145636e95
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.