CVE Vulnerabilities

CVE-2024-6381

Integer Overflow to Buffer Overflow

Published: Jul 02, 2024 | Modified: Nov 03, 2025
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The bson_strfreev function in the MongoDB C driver library may be susceptible to an integer overflow where the function will try to free memory at a negative offset. This may result in memory corruption. This issue affected libbson versions prior to 1.26.2

Weakness

The product performs a calculation to determine how much memory to allocate, but an integer overflow can occur that causes less memory to be allocated than expected, leading to a buffer overflow.

Affected Software

NameVendorStart VersionEnd Version
LibbsonMongodb*1.26.2 (excluding)
Mongo-c-driverUbuntuesm-apps/focal*
Mongo-c-driverUbuntuesm-apps/jammy*
Mongo-c-driverUbuntuesm-apps/noble*
Mongo-c-driverUbuntufocal*
Mongo-c-driverUbuntujammy*
Mongo-c-driverUbuntumantic*
Mongo-c-driverUbuntunoble*
Mongo-c-driverUbuntuupstream*

References