The bson_strfreev function in the MongoDB C driver library may be susceptible to an integer overflow where the function will try to free memory at a negative offset. This may result in memory corruption. This issue affected libbson versions prior to 1.26.2
{
"binaries": [
{
"binary_version": "1.16.1-1ubuntu0.1~esm1",
"binary_name": "libbson-1.0-0"
},
{
"binary_version": "1.16.1-1ubuntu0.1~esm1",
"binary_name": "libbson-dev"
},
{
"binary_version": "1.16.1-1ubuntu0.1~esm1",
"binary_name": "libmongoc-1.0-0"
},
{
"binary_version": "1.16.1-1ubuntu0.1~esm1",
"binary_name": "libmongoc-dev"
}
],
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}
{
"binaries": [
{
"binary_version": "1.21.0-1ubuntu0.1~esm1",
"binary_name": "libbson-1.0-0"
},
{
"binary_version": "1.21.0-1ubuntu0.1~esm1",
"binary_name": "libbson-dev"
},
{
"binary_version": "1.21.0-1ubuntu0.1~esm1",
"binary_name": "libmongoc-1.0-0"
},
{
"binary_version": "1.21.0-1ubuntu0.1~esm1",
"binary_name": "libmongoc-dev"
}
],
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}
{
"binaries": [
{
"binary_version": "1.26.0-1.1ubuntu2+esm1",
"binary_name": "libbson-1.0-0t64"
},
{
"binary_version": "1.26.0-1.1ubuntu2+esm1",
"binary_name": "libbson-dev"
},
{
"binary_version": "1.26.0-1.1ubuntu2+esm1",
"binary_name": "libmongoc-1.0-0t64"
},
{
"binary_version": "1.26.0-1.1ubuntu2+esm1",
"binary_name": "libmongoc-dev"
}
],
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}