Heap-based buffer overflow in MongoDB driver for C - CVE-2025-0755

 

Heap-based buffer overflow in MongoDB driver for C - CVE-2025-0755

Published: July 3, 2025


Vulnerability identifier: #VU112138
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-0755
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within various bson_append functions. A remote attacker can pass specially crafted data to the application, trigger a heap-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

MongoDB driver for C
Watson Query on Cloud Pak for Data
Data Virtualization (DV) on Cloud Pak for Data (CPD)
Db2 Big SQL
IBM OpenPages with Watson
IBM Security Guardium Key Lifecycle Manager (GKLM)
IBM Security Verify Governance
MongoDB
Ubuntu
mongo-c-driver (Ubuntu package)

How to mitigate CVE-2025-0755

Install updates from vendor's website.

MongoDB driver for C - update to 1.27.5
Data Virtualization (DV) on Cloud Pak for Data (CPD) - update to 3.2.1
MongoDB - addressed in versions 7.0.16, 8.0.1
Db2 Big SQL - update to 8.1
IBM OpenPages with Watson - update to 9.1.2
mongo-c-driver (Ubuntu package) - addressed in versions 1.16.1-1ubuntu0.1~esm1, 1.21.0-1ubuntu0.1~esm1, 1.26.0-1.1ubuntu2+esm1

External References

Related Security Bulletins