Release date:
2026-08-04 09:28:05 UTC
Description:
* SECURITY UPDATE: mongos explain authorization bypass via inner command
generic arguments
- debian/patches/CVE-2025-3084.patch: rewrite
ClusterExplain::wrapAsExplain in src/mongo/s/commands/cluster_explain.cpp
to prune generic arguments (lsid, $clusterTime, writeConcern,
$queryOptions/$readPreference, etc.) from the inner command envelope
forwarded to shards through the explain wrapper, keeping readConcern
propagated on the outer explain command; blocks smuggling of top-level
authorization arguments past mongos.
- CVE-2025-3084
Updated packages:
-
mongodb42_4.2.25-1+tuxcare.els16_amd64.deb
sha:9229722795034161d9a9ad4bc7d7ec8ddf60cd5a
-
mongodb42-mongos_4.2.25-1+tuxcare.els16_amd64.deb
sha:1ff40fe2a342eb7511e2bbe9d274e861a2bec1ca
-
mongodb42-server_4.2.25-1+tuxcare.els16_amd64.deb
sha:d67cdd82bc204d6735193d0e35314698f3571ecb
-
mongodb42-shell_4.2.25-1+tuxcare.els16_amd64.deb
sha:44ad3f64c06088c303c1b6eb14f2e139d461679a
-
mongodb42_4.2.25-1+tuxcare.els16_arm64.deb
sha:eaa1e62bddcead0073383a4a8bf53cf37c516de4
-
mongodb42-mongos_4.2.25-1+tuxcare.els16_arm64.deb
sha:833e30e1950d45f9b972280039776647cad32185
-
mongodb42-server_4.2.25-1+tuxcare.els16_arm64.deb
sha:61208b62feb2ea0c6f1a25ba2b7b95c8275ad0e1
-
mongodb42-shell_4.2.25-1+tuxcare.els16_arm64.deb
sha:4989ec1269f860b8f1f582da4c8d32dc8eaab4b5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.