DEBIAN-CVE-2026-84968

Source
https://security-tracker.debian.org/tracker/CVE-2026-84968
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-84968.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-84968
Upstream
Published
2026-09-03T18:17:33Z
Modified
2026-09-11T08:47:38Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially formed input to have a small amount of adjacent process memory copied into an error message that is returned to application code. This may result in unintended disclosure of limited memory contents.

References

Affected packages

Debian:12 / php-mongodb

Package

Name
php-mongodb
Purl
pkg:deb/debian/php-mongodb?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.15.0+1.11.1+1.9.2+1.7.5-1
1.19.3-1
1.19.4-2
1.19.4-3~exp2
1.19.4-3~exp3
1.19.4-3~exp4
1.20.0-1
1.20.1-1
1.21.0-1
2.*
2.0.0-1
2.1.0-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-84968.json"

Debian:13 / php-mongodb

Package

Name
php-mongodb
Purl
pkg:deb/debian/php-mongodb?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.0.0-1
2.1.0-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-84968.json"

Debian:14 / php-mongodb

Package

Name
php-mongodb
Purl
pkg:deb/debian/php-mongodb?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.0.0-1
2.1.0-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-84968.json"