Heap-based buffer overflow in MongoDB driver for C - CVE-2025-0755
Published: July 3, 2025
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within various bson_append functions. A remote attacker can pass specially crafted data to the application, trigger a heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Watson Query on Cloud Pak for Data
Data Virtualization (DV) on Cloud Pak for Data (CPD)
Db2 Big SQL
IBM OpenPages with Watson
IBM Security Guardium Key Lifecycle Manager (GKLM)
IBM Security Verify Governance
MongoDB
Ubuntu
mongo-c-driver (Ubuntu package)
How to mitigate CVE-2025-0755
Data Virtualization (DV) on Cloud Pak for Data (CPD) - update to 3.2.1
MongoDB - addressed in versions 7.0.16, 8.0.1
Db2 Big SQL - update to 8.1
IBM OpenPages with Watson - update to 9.1.2
mongo-c-driver (Ubuntu package) - addressed in versions 1.16.1-1ubuntu0.1~esm1, 1.21.0-1ubuntu0.1~esm1, 1.26.0-1.1ubuntu2+esm1
External References
Related Security Bulletins
- Remote code execution in MongoDB driver for C
- MongoDB Server update for MongoDB driver for C
- Ubuntu update for mongo-c-driver
- Multiple vulnerabilities in IBM Security Guardium Key Lifecycle Manager
- Multiple vulnerabilities in IBM Data Virtualization on IBM Software Hub
- Multiple vulnerabilities in IBM Security Verify Governance
- Multiple vulnerabilities in IBM OpenPages
- Multiple vulnerabilities in IBM Big SQL on IBM Cloud Pak for Data