[CLSA-2026:1785833637] Fix CVE(s): CVE-2025-3084
Type:
security
Severity:
Low
Release date:
2026-08-04 08:54:08 UTC
Description:
* SECURITY UPDATE: mongos explain authorization bypass via inner command generic arguments - debian/patches/CVE-2025-3084.patch: rewrite ClusterExplain::wrapAsExplain in src/mongo/s/commands/cluster_explain.cpp to prune generic arguments (lsid, $clusterTime, writeConcern, $queryOptions/$readPreference, etc.) from the inner command envelope forwarded to shards through the explain wrapper, keeping readConcern propagated on the outer explain command; blocks smuggling of top-level authorization arguments past mongos. - CVE-2025-3084
CVEs fixed:
Updated packages:
  • mongodb42_4.2.25-1+tuxcare.els16_amd64.deb
    sha:9229722795034161d9a9ad4bc7d7ec8ddf60cd5a
  • mongodb42-mongos_4.2.25-1+tuxcare.els16_amd64.deb
    sha:8bf3bbf76530dd8bf02665bc2474fbece899df2b
  • mongodb42-server_4.2.25-1+tuxcare.els16_amd64.deb
    sha:c7ca3616dda6422cf4cdb6e96a5786744a9576fb
  • mongodb42-shell_4.2.25-1+tuxcare.els16_amd64.deb
    sha:f9d77c8724df3d477f66b38015a2ecddef3f06e0
  • mongodb42_4.2.25-1+tuxcare.els16_arm64.deb
    sha:eaa1e62bddcead0073383a4a8bf53cf37c516de4
  • mongodb42-mongos_4.2.25-1+tuxcare.els16_arm64.deb
    sha:75f5c15a97bf744d075447f896527a4391ec67eb
  • mongodb42-server_4.2.25-1+tuxcare.els16_arm64.deb
    sha:c99aff8b979f56ac6618470d0054ac859f7ce5e4
  • mongodb42-shell_4.2.25-1+tuxcare.els16_arm64.deb
    sha:b26c9520ba248064f99e5a08b844550fc293a90b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.