DEBIAN-CVE-2026-106431

Source
https://security-tracker.debian.org/tracker/CVE-2026-106431
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-106431.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-106431
Upstream
  • CVE-2026-106431
Published
2026-10-08T19:16:59Z
Modified
2026-10-09T21:00:15Z
Severity
  • 5.9 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

An off-by-one error in the BSON bulk document writer in the MongoDB C Driver can write one zero byte immediately past a heap allocation when a document ends at a specific buffer boundary. An actor who can influence the size of documents serialized by an embedding application can corrupt adjacent process memory or terminate the process. Reaching this issue requires the application to use the BSON bulk-writer API and produce a precise cumulative document size.

References

Affected packages

Debian:12 / mongo-c-driver

Package

Name
mongo-c-driver
Purl
pkg:deb/debian/mongo-c-driver?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.23.1-1
1.23.1-1+deb12u1
1.23.1-1+deb12u2
1.23.1-1+deb12u3
1.24.1-1
1.24.2-1
1.24.3-1
1.24.4-1
1.25.0-1
1.25.1-1
1.25.2-1
1.25.4-1
1.25.4-1.1~exp1
1.26.0-1
1.26.0-1.1~exp1
1.26.0-1.1
1.26.1-1
1.26.2-1
1.27.0-1
1.27.1-1
1.27.2-1
1.27.3-1
1.27.4-1
1.27.5-1
1.27.6-1
1.28.0-1
1.28.1-1
1.29.0-1
1.29.1-1
1.29.2-1
1.30.0-1
1.30.1-1
1.30.2-1
1.30.3-1
1.30.4-1
2.*
2.0.2-1
2.1.0-1
2.1.1-1
2.1.2-1
2.2.0-1
2.2.1-1
2.2.2-1
2.2.3-1
2.2.4-1
2.3.0-1
2.3.1-1
2.3.2-1
2.3.3-1
2.4.0-1
2.5.0-1
2.5.1-1
2.5.2-1
2.5.3-1
2.5.5-1
2.5.6-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-106431.json"

Debian:13 / mongo-c-driver

Package

Name
mongo-c-driver
Purl
pkg:deb/debian/mongo-c-driver?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.30.4-1
1.30.4-1+deb13u1
1.30.4-1+deb13u2
1.30.4-1+deb13u3
2.*
2.0.2-1
2.1.0-1
2.1.1-1
2.1.2-1
2.2.0-1
2.2.1-1
2.2.2-1
2.2.3-1
2.2.4-1
2.3.0-1
2.3.1-1
2.3.2-1
2.3.3-1
2.4.0-1
2.5.0-1
2.5.1-1
2.5.2-1
2.5.3-1
2.5.5-1
2.5.6-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-106431.json"

Debian:14 / mongo-c-driver

Package

Name
mongo-c-driver
Purl
pkg:deb/debian/mongo-c-driver?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.30.4-1
2.*
2.0.2-1
2.1.0-1
2.1.1-1
2.1.2-1
2.2.0-1
2.2.1-1
2.2.2-1
2.2.3-1
2.2.4-1
2.3.0-1
2.3.1-1
2.3.2-1
2.3.3-1
2.4.0-1
2.5.0-1
2.5.1-1
2.5.2-1
2.5.3-1
2.5.5-1
2.5.6-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-106431.json"