Release date:
2026-08-04 08:54:08 UTC
Description:
* SECURITY UPDATE: mongos explain authorization bypass via inner command
generic arguments
- debian/patches/CVE-2025-3084.patch: rewrite
ClusterExplain::wrapAsExplain in src/mongo/s/commands/cluster_explain.cpp
to prune generic arguments (lsid, $clusterTime, writeConcern,
$queryOptions/$readPreference, etc.) from the inner command envelope
forwarded to shards through the explain wrapper, keeping readConcern
propagated on the outer explain command; blocks smuggling of top-level
authorization arguments past mongos.
- CVE-2025-3084
Updated packages:
-
mongodb42_4.2.25-1+tuxcare.els16_amd64.deb
sha:9229722795034161d9a9ad4bc7d7ec8ddf60cd5a
-
mongodb42-mongos_4.2.25-1+tuxcare.els16_amd64.deb
sha:8bf3bbf76530dd8bf02665bc2474fbece899df2b
-
mongodb42-server_4.2.25-1+tuxcare.els16_amd64.deb
sha:c7ca3616dda6422cf4cdb6e96a5786744a9576fb
-
mongodb42-shell_4.2.25-1+tuxcare.els16_amd64.deb
sha:f9d77c8724df3d477f66b38015a2ecddef3f06e0
-
mongodb42_4.2.25-1+tuxcare.els16_arm64.deb
sha:eaa1e62bddcead0073383a4a8bf53cf37c516de4
-
mongodb42-mongos_4.2.25-1+tuxcare.els16_arm64.deb
sha:75f5c15a97bf744d075447f896527a4391ec67eb
-
mongodb42-server_4.2.25-1+tuxcare.els16_arm64.deb
sha:c99aff8b979f56ac6618470d0054ac859f7ce5e4
-
mongodb42-shell_4.2.25-1+tuxcare.els16_arm64.deb
sha:b26c9520ba248064f99e5a08b844550fc293a90b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.