[CLSA-2026:1789722975] Fix CVE(s): CVE-2025-10061
Type:
security
Severity:
Moderate
Release date:
2026-09-18 09:16:32 UTC
Description:
* SECURITY UPDATE: server crash through unauthorized use of the internal $doingMerge flag in $group aggregation - debian/patches/CVE-2025-10061.patch: restrict $doingMerge to internal clients and raise a user-facing error instead of a hard assertion when an accumulator receives unexpected input on the merging pass - CVE-2025-10061
CVEs fixed:
Updated packages:
  • mongodb42_4.2.25-1+tuxcare.els18_amd64.deb
    sha:9878ed2d7fe4f47065791bab139372e9d2ff21bf
  • mongodb42-mongos_4.2.25-1+tuxcare.els18_amd64.deb
    sha:33109151932d21f2ff3518fb262ea81f5f466c95
  • mongodb42-server_4.2.25-1+tuxcare.els18_amd64.deb
    sha:6948f089663c8216e058f1345d049572cb621884
  • mongodb42-shell_4.2.25-1+tuxcare.els18_amd64.deb
    sha:25b617a4bf23d717df281a575c32da978e9e96bb
  • mongodb42_4.2.25-1+tuxcare.els18_arm64.deb
    sha:fa331bae5df68e4305090e6d3752aae8915f5bb3
  • mongodb42-mongos_4.2.25-1+tuxcare.els18_arm64.deb
    sha:389c53b5fdd7f7c13a8d675d02101ebaf6f95010
  • mongodb42-server_4.2.25-1+tuxcare.els18_arm64.deb
    sha:2774ea6b28d3d0eee863f7137c836d7508224ed3
  • mongodb42-shell_4.2.25-1+tuxcare.els18_arm64.deb
    sha:ee8ab5b5e6ea862e8d39baebf9923c3f6b03abd9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.