The bson_strfreev function in the MongoDB C driver library may be susceptible to an integer overflow where the function will try to free memory at a negative offset. This may result in memory corruption. This issue affected libbson versions prior to 1.26.2
CVSS Details
- CVSS 3.1 Base Score: 4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libbson-xs-perlUpgrade mongo-c-driver | May 12, 2025 | Jul 2, 2024 |
| Ubuntu | — | Upgrade libbson-1.0-0 (Ubuntu Pro)Upgrade libmongoc-1.0-0 (Ubuntu Pro)Upgrade libmongoc-1.0-0t64 (Ubuntu Pro)Upgrade libbson-dev (Ubuntu Pro)Upgrade libbson-1.0-0t64 (Ubuntu Pro)Upgrade libmongoc-dev (Ubuntu Pro) | Jun 26, 2025 | Jul 2, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub