CVE-2025-0755
18.03.2025, 09:15
The various bson_appendfunctions in the MongoDB C driver library may be susceptible to buffer overflow when performing operations that could result in a final BSON document which exceeds the maximum allowable size (INT32_MAX), resulting in a segmentation fault and possible application crash. This issue affected libbson versions prior to 1.27.5, MongoDB Server v8.0 versions prior to 8.0.1 and MongoDB Server v7.0 versions prior to 7.0.16Enginsight
Vendor | Product | Version |
---|---|---|
mongodb | libbson | 𝑥 < 1.27.5 |
mongodb | mongodb | 7.0.0 ≤ 𝑥 < 7.0.16 |
mongodb | mongodb | 8.0.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases