jira.mongodb.org
https://jira.mongodb.org/browse/CDRIVER-5628 CVE-2024-6383
MEDIUM
MongoDB C Driver bson_string_append may be vulnerable to a buffer overflow
Record summary
CVE-2024-6383 has a selected CVSS score of 5.3 (medium).
Description
The bson_string_append function in MongoDB C Driver may be vulnerable to a buffer overflow where the function might attempt to allocate too small of buffer and may lead to memory corruption of neighbouring heap memory. This issue affects libbson versions prior to 1.27.1
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 5, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
libbsonBrowse MongoDB Inc / libbsonDefault status: unaffected | CVE List | Before 1.27.1 | affected |
References
5lists.debian.org
https://lists.debian.org/debian-lts-announce/2025/05/msg00012.html lists.debian.org
https://lists.debian.org/debian-lts-announce/2025/05/msg00027.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-6383 security.netapp.com
https://security.netapp.com/advisory/ntap-20241004-0001