MongoDB C Driver Library Vulnerable to Integer Overflow, May Cause Memory Corruption
CVE-2024-6381

Currently unrated

Key Information:

Vendor

MongoDB

Vendor
CVE Published:
2 July 2024

What is CVE-2024-6381?

The bson_strfreev function in the MongoDB C driver library may be susceptible to an integer overflow where the function will try to free memory at a negative offset. This may result in memory corruption. This issue affected libbson versions prior to 1.26.2

References

Timeline

  • Vulnerability published

.
CVE-2024-6381 : MongoDB C Driver Library Vulnerable to Integer Overflow, May Cause Memory Corruption