| Name | CVE-2026-84969 |
| Description | A memory-handling error in the BSON-to-JSON conversion helpers of the MongoDB C Driver can write a small number of bytes past the end of a heap buffer when a binary field is encoded and the output is cut short at a caller-configured length limit. A party who supplies the document content, with no privileges on the application that links the driver, may cause a small amount of data outside the intended buffer to be altered. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| mongo-c-driver (PTS) | bookworm | 1.23.1-1+deb12u3 | fixed |
| trixie | 1.30.4-1+deb13u3 | vulnerable | |
| forky, sid | 2.5.3-1 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| mongo-c-driver | source | bookworm | (not affected) | |||
| mongo-c-driver | source | (unstable) | 2.5.2-1 |
[trixie] - mongo-c-driver <no-dsa> (Minor issue)
[bookworm] - mongo-c-driver <not-affected> (Vulnerable code introduced later)
https://jira.mongodb.org/browse/CDRIVER-6410
Fixed by: https://github.com/mongodb/mongo-c-driver/commit/4229afa3bb4d0842edd5ee8da0f5143bd563e0bd (2.5.2)
Fixed by: https://github.com/mongodb/mongo-c-driver/commit/08d0cfaaf08a54d7e87a5e5fa8d38251bf0eeca6 (1.30.9)
Introduced by: https://github.com/mongodb/mongo-c-driver/commit/f2c1bb7989177fa2ddba1a915e8423e46ee1defe (1.30.0)