Release date:
2026-09-18 09:16:32 UTC
Description:
* SECURITY UPDATE: server crash through unauthorized use of the internal
$doingMerge flag in $group aggregation
- debian/patches/CVE-2025-10061.patch: restrict $doingMerge to internal
clients and raise a user-facing error instead of a hard assertion when
an accumulator receives unexpected input on the merging pass
- CVE-2025-10061
Updated packages:
-
mongodb42_4.2.25-1+tuxcare.els18_amd64.deb
sha:9878ed2d7fe4f47065791bab139372e9d2ff21bf
-
mongodb42-mongos_4.2.25-1+tuxcare.els18_amd64.deb
sha:33109151932d21f2ff3518fb262ea81f5f466c95
-
mongodb42-server_4.2.25-1+tuxcare.els18_amd64.deb
sha:6948f089663c8216e058f1345d049572cb621884
-
mongodb42-shell_4.2.25-1+tuxcare.els18_amd64.deb
sha:25b617a4bf23d717df281a575c32da978e9e96bb
-
mongodb42_4.2.25-1+tuxcare.els18_arm64.deb
sha:fa331bae5df68e4305090e6d3752aae8915f5bb3
-
mongodb42-mongos_4.2.25-1+tuxcare.els18_arm64.deb
sha:389c53b5fdd7f7c13a8d675d02101ebaf6f95010
-
mongodb42-server_4.2.25-1+tuxcare.els18_arm64.deb
sha:2774ea6b28d3d0eee863f7137c836d7508224ed3
-
mongodb42-shell_4.2.25-1+tuxcare.els18_arm64.deb
sha:ee8ab5b5e6ea862e8d39baebf9923c3f6b03abd9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.