CVE-2025-40906

NameCVE-2025-40906
DescriptionBSON::XS versions 0.8.4 and earlier for Perl includes a bundled libbson 1.1.7, which has several vulnerabilities. Those include CVE-2017-14227, CVE-2018-16790, CVE-2023-0437, CVE-2024-6381, CVE-2024-6383, and CVE-2025-0755. BSON-XS was the official Perl XS implementation of MongoDB's BSON serialization, but this distribution has reached its end of life as of August 13, 2020 and is no longer supported.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libbson-xs-perl (PTS)bullseye0.8.4-1vulnerable
bullseye (security)0.8.4-1+deb11u1vulnerable
bookworm0.8.4-2+deb12u1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libbson-xs-perlsource(unstable)(unfixed)unimportant

Notes

https://lists.security.metacpan.org/cve-announce/msg/29655123/
The CVE assignment is specific to BSON::XS versions 0.8.4 bundling libbson 1.1.7
with several CVEs affected. Fixes for those were covered in the corresponding
CVEs.

Search for package or bug name: Reporting problems