[CLSA-2026:1789722667] Fix CVE(s): CVE-2025-10061
Type:
security
Severity:
Moderate
Release date:
2026-09-18 09:11:24 UTC
Description:
* SECURITY UPDATE: server crash through unauthorized use of the internal $doingMerge flag in $group aggregation - debian/patches/CVE-2025-10061.patch: restrict $doingMerge to internal clients and raise a user-facing error instead of a hard assertion when an accumulator receives unexpected input on the merging pass - CVE-2025-10061
CVEs fixed:
Updated packages:
  • mongodb42_4.2.25-1+tuxcare.els18_amd64.deb
    sha:9878ed2d7fe4f47065791bab139372e9d2ff21bf
  • mongodb42-mongos_4.2.25-1+tuxcare.els18_amd64.deb
    sha:4a74870cbeb4a344a6f0fcd0fdf722708ca1155c
  • mongodb42-server_4.2.25-1+tuxcare.els18_amd64.deb
    sha:cabe89d682a843a66d2b01b6e9d07f9a105b31b6
  • mongodb42-shell_4.2.25-1+tuxcare.els18_amd64.deb
    sha:fa6139cfa0d689312d1bf4bdb1127cab4b86d8ba
  • mongodb42_4.2.25-1+tuxcare.els18_arm64.deb
    sha:fa331bae5df68e4305090e6d3752aae8915f5bb3
  • mongodb42-mongos_4.2.25-1+tuxcare.els18_arm64.deb
    sha:bcc7431eebb6e48224d9c4361c318ae9c41ed03e
  • mongodb42-server_4.2.25-1+tuxcare.els18_arm64.deb
    sha:9eec4953b91c5fcb9f96fe510da630eb4bc1b5d0
  • mongodb42-shell_4.2.25-1+tuxcare.els18_arm64.deb
    sha:4f32e8a20e69e5c7b8b4209acdf8db3566fcec41
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.