[CLSA-2026:1785832805] Fix CVE(s): CVE-2025-6707
Type:
security
Severity:
Moderate
Release date:
2026-08-04 08:40:17 UTC
Description:
* SECURITY UPDATE: race condition in user privilege cache invalidation - debian/patches/CVE-2025-6707.patch: defer user cache invalidation in AuthzManagerLogOpHandler until the enclosing WriteUnitOfWork commits, by moving _invalidateRelevantCacheData() out of the constructor and into commit() in src/mongo/db/auth/authz_manager_external_state_local.cpp - CVE-2025-6707
CVEs fixed:
Updated packages:
  • mongodb42_4.2.25-1+tuxcare.els15_amd64.deb
    sha:4159e340ecc0e532a39711e7e99cf0e0c0218cfd
  • mongodb42-mongos_4.2.25-1+tuxcare.els15_amd64.deb
    sha:3dd918f8651f4d0b133c18777eeb6132b3f14ef8
  • mongodb42-server_4.2.25-1+tuxcare.els15_amd64.deb
    sha:cd1bcc18bc6b08466c09e6917f7552729f6dc4d4
  • mongodb42-shell_4.2.25-1+tuxcare.els15_amd64.deb
    sha:02b9851cee62fc6c9cec9b9bd8e77057cb908dd0
  • mongodb42_4.2.25-1+tuxcare.els15_arm64.deb
    sha:8b007cd8196f81862f5a6a0a5caf111e1bc1b4e5
  • mongodb42-mongos_4.2.25-1+tuxcare.els15_arm64.deb
    sha:ac7729551fade175d4c6bfecab1f84139697d21d
  • mongodb42-server_4.2.25-1+tuxcare.els15_arm64.deb
    sha:67ec37681eb37406c83a6a38dee6d3e1f532d53e
  • mongodb42-shell_4.2.25-1+tuxcare.els15_arm64.deb
    sha:b4d895d97b9a0e91fc746275dea4223ee4091feb
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.