SB2026092291 - Fedora EPEL 9 update for mongo-c-driver
Published: September 22, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Improper Neutralization of Special Elements in Data Query Logic (CVE-ID: CVE-2026-88036)
CWE-ID: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic
CVSSv4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose stored file content or delete GridFS file chunks.
The vulnerability exists due to improper neutralization of special elements in data query logic in the GridFS component when processing caller-supplied structured file identifiers. A remote user can supply a structured file identifier that is interpreted as a query condition to disclose stored file content or delete GridFS file chunks.
2) Heap-based buffer overflow (CVE-ID: CVE-2026-88035)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a heap-based buffer overflow in the SASL username canonicalization logic when processing an unusually large username value in the driver's connection settings. A local user can configure the driver's connection settings with an unusually large username to cause a denial of service.
Exploitation requires a build with the optional external SASL authentication backend and a connection configured to use it.
Remediation
Install update from vendor's website.