Skip to content
Fedora 45 Updates Address Critical MongoDB Driver Vulnerabilities

Fedora 45 Updates Address Critical MongoDB Driver Vulnerabilities

First seen 13 Sep 2026, 11:41 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 13, 2026 at 12:58 UTC
  • Critical vulnerabilities fixed in Fedora 45 MongoDB packages.
  • Out-of-bounds read and OCSP parsing issues addressed.
  • Users must update their systems immediately to mitigate risks.

Fedora 45 has released critical updates for two MongoDB-related packages: php-pecl-mongodb2 and mongo-c-driver. The php-pecl-mongodb2 package fixes an out-of-bounds read vulnerability (CVE-2026-84968) that could lead to information disclosure. The mongo-c-driver addresses multiple vulnerabilities, including OCSP parsing issues (CVE-2026-84964) and unsafe casts during JSON parsing (CVE-2026-84965). These vulnerabilities affect systems using Fedora 45 with the respective packages installed. Users are advised to apply updates immediately to mitigate risks. The updates were released on September 13, 2026, and can be installed using the 'dnf' update program. The vulnerabilities were discovered and patched by developers, ensuring that the affected components are now secure.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-08-27
CVE-2026-81524 published
Database and collection name validation issues reported in mongo-c-driver affecting Fedora 45.
Linuxsecurity
2026-09-03
Multiple CVEs published
CVE-2026-84963, CVE-2026-84964, CVE-2026-84965, CVE-2026-84968, and CVE-2026-84969 disclosed, highlighting critical vulnerabilities in MongoDB drivers.
Linuxsecurity
2026-09-03
CVE-2026-84963 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-03
CVE-2026-84964 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-03
CVE-2026-84968 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-03
CVE-2026-84969 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-03
CVE-2026-84965 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-13
Fedora 45 updates released
Fedora 45 released important updates for php-pecl-mongodb2 and mongo-c-driver to fix critical vulnerabilities.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track Fedora and CVE-2026-81524 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed