CVE-2024-6381 Information

Description

The bson_strfreev function in the MongoDB C driver library may be susceptible to an integer overflow where the function will try to free memory at a negative offset. This may result in memory corruption. This issue affected libbson versions prior to 1.26.2

Reference

https://jira.mongodb.org/browse/CDRIVER-5622

Share on: