[CLSA-2026:1785835675] Fix CVE(s): CVE-2025-3084
Type:
security
Severity:
Low
Release date:
2026-08-04 09:28:05 UTC
Description:
* SECURITY UPDATE: mongos explain authorization bypass via inner command generic arguments - debian/patches/CVE-2025-3084.patch: rewrite ClusterExplain::wrapAsExplain in src/mongo/s/commands/cluster_explain.cpp to prune generic arguments (lsid, $clusterTime, writeConcern, $queryOptions/$readPreference, etc.) from the inner command envelope forwarded to shards through the explain wrapper, keeping readConcern propagated on the outer explain command; blocks smuggling of top-level authorization arguments past mongos. - CVE-2025-3084
CVEs fixed:
Updated packages:
  • mongodb42_4.2.25-1+tuxcare.els16_amd64.deb
    sha:9229722795034161d9a9ad4bc7d7ec8ddf60cd5a
  • mongodb42-mongos_4.2.25-1+tuxcare.els16_amd64.deb
    sha:1ff40fe2a342eb7511e2bbe9d274e861a2bec1ca
  • mongodb42-server_4.2.25-1+tuxcare.els16_amd64.deb
    sha:d67cdd82bc204d6735193d0e35314698f3571ecb
  • mongodb42-shell_4.2.25-1+tuxcare.els16_amd64.deb
    sha:44ad3f64c06088c303c1b6eb14f2e139d461679a
  • mongodb42_4.2.25-1+tuxcare.els16_arm64.deb
    sha:eaa1e62bddcead0073383a4a8bf53cf37c516de4
  • mongodb42-mongos_4.2.25-1+tuxcare.els16_arm64.deb
    sha:833e30e1950d45f9b972280039776647cad32185
  • mongodb42-server_4.2.25-1+tuxcare.els16_arm64.deb
    sha:61208b62feb2ea0c6f1a25ba2b7b95c8275ad0e1
  • mongodb42-shell_4.2.25-1+tuxcare.els16_arm64.deb
    sha:4989ec1269f860b8f1f582da4c8d32dc8eaab4b5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.