[CLSA-2026:1785833459] Fix CVE(s): CVE-2025-6707
Type:
security
Severity:
Moderate
Release date:
2026-08-04 08:51:10 UTC
Description:
* SECURITY UPDATE: race condition in user privilege cache invalidation - debian/patches/CVE-2025-6707.patch: defer user cache invalidation in AuthzManagerLogOpHandler until the enclosing WriteUnitOfWork commits, by moving _invalidateRelevantCacheData() out of the constructor and into commit() in src/mongo/db/auth/authz_manager_external_state_local.cpp - CVE-2025-6707
CVEs fixed:
Updated packages:
  • mongodb42_4.2.25-1+tuxcare.els15_amd64.deb
    sha:4159e340ecc0e532a39711e7e99cf0e0c0218cfd
  • mongodb42-mongos_4.2.25-1+tuxcare.els15_amd64.deb
    sha:f304a2becd7206e68c83b560ad92fd89a47d849d
  • mongodb42-server_4.2.25-1+tuxcare.els15_amd64.deb
    sha:c4a2529df55d40d62dd0b0dd741d0eb3b409bdb6
  • mongodb42-shell_4.2.25-1+tuxcare.els15_amd64.deb
    sha:0aaf8097969e7cd131c823ffbf07e0d4d21743f3
  • mongodb42_4.2.25-1+tuxcare.els15_arm64.deb
    sha:8b007cd8196f81862f5a6a0a5caf111e1bc1b4e5
  • mongodb42-mongos_4.2.25-1+tuxcare.els15_arm64.deb
    sha:00160f4664775ccbe499112b3577d1f1634fdad9
  • mongodb42-server_4.2.25-1+tuxcare.els15_arm64.deb
    sha:b60b5f6bd7b6d33c06dcb6432a3aa30f7b7a5d31
  • mongodb42-shell_4.2.25-1+tuxcare.els15_arm64.deb
    sha:7e9abb751686b9f894c0b43f42576e4829248dd6
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.