CVE-2026-106431

NameCVE-2026-106431
DescriptionAn off-by-one error in the BSON bulk document writer in the MongoDB C Driver can write one zero byte immediately past a heap allocation when a document ends at a specific buffer boundary. An actor who can influence the size of documents serialized by an embedding application can corrupt adjacent process memory or terminate the process. Reaching this issue requires the application to use the BSON bulk-writer API and produce a precise cumulative document size.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
mongo-c-driver (PTS)bookworm1.23.1-1+deb12u3vulnerable
trixie1.30.4-1+deb13u3vulnerable
forky2.5.5-1vulnerable
sid2.5.6-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
mongo-c-driversource(unstable)2.5.6-1

Notes

[trixie] - mongo-c-driver <no-dsa> (Minor issue)
https://jira.mongodb.org/browse/CDRIVER-6418
Fixed by: https://github.com/mongodb/mongo-c-driver/commit/bddaffdabdb449d8ee5e8b28f9a82afd03cd42aa (2.5.6)
Fixed by: https://github.com/mongodb/mongo-c-driver/commit/70d96b8f28974e02cc966a00953dc3d8c308b8ff (1.30.13)

Search for package or bug name: Reporting problems