CVE Vulnerabilities

CVE-2023-0437

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Jan 12, 2024 | Modified: Nov 03, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

When calling bson_utf8_validateĀ on some inputs a loop with an exit condition that cannot be reached may occur, i.e. an infinite loop. This issue affects All MongoDB C Driver versions prior to versions 1.25.0.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

NameVendorStart VersionEnd Version
C_driverMongodb*1.25.0 (excluding)
MongodbUbuntubionic*
MongodbUbuntufocal*
MongodbUbuntutrusty*
MongodbUbuntutrusty/esm*
MongodbUbuntuxenial*

References