[CLSA-2026:1784645069] Fix CVE(s): CVE-2026-1847
Type:
security
Severity:
Important
Release date:
2026-07-21 14:44:56 UTC
Description:
* SECURITY UPDATE: wire-message-size DoS via oversized OpMsg body reads - debian/patches/CVE-2026-1847.patch: introduce a slightly higher BSONObj size limit for wire messages (SERVER-113532); adds BSONObjMaxWireMessageSize and BSONObj::WireMessageSizeTrait in src/mongo/bson/{bsonobj.{cpp,h},util/builder.h}, threads the trait through src/mongo/db/commands/getmore_cmd.cpp, and validates op_msg body sections via a new WireMessagePayload type in src/mongo/rpc/{op_msg.cpp,object_check.h,wire_message_payload.h} with accompanying data_type_wire_message_payload_test.cpp coverage. - CVE-2026-1847
CVEs fixed:
Updated packages:
  • mongodb5_5.0.31-1+tuxcare.els13_amd64.deb
    sha:7729eb9e98e3f41fc380eb7568f4be669326523c
  • mongodb5-mongos_5.0.31-1+tuxcare.els13_amd64.deb
    sha:c6c4a0f345a130b7374e1944775b530977bd7eb3
  • mongodb5-server_5.0.31-1+tuxcare.els13_amd64.deb
    sha:49e010149db654638a9d615cb012832336c8c878
  • mongodb5-shell_5.0.31-1+tuxcare.els13_amd64.deb
    sha:cc7efe72ec1f70f9dedfe2574721378e2d1b32d9
  • mongodb5_5.0.31-1+tuxcare.els13_arm64.deb
    sha:be7e0e2fa379e312a9aeada4ff387a3988f9fbf3
  • mongodb5-mongos_5.0.31-1+tuxcare.els13_arm64.deb
    sha:8317a3cb9eb382f0f9c511faaf5853fe3c3b185d
  • mongodb5-server_5.0.31-1+tuxcare.els13_arm64.deb
    sha:81c884cd70b51bf8c6ea5ace792bf45811e369ab
  • mongodb5-shell_5.0.31-1+tuxcare.els13_arm64.deb
    sha:03d3bed4f0157b92088671c2da893812d073c2a1
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.