CVE Vulnerabilities

CVE-2025-12119

Expired Pointer Dereference

Published: Nov 18, 2025 | Modified: Jan 14, 2026
CVSS 3.x
3.3
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A mongoc_bulk_operation_t may read invalid memory if large options are passed.

Weakness

The product dereferences a pointer that contains a location for memory that was previously valid, but is no longer valid.

Affected Software

NameVendorStart VersionEnd Version
C_driverMongodb1.9.0 (including)1.30.6 (excluding)
C_driverMongodb2.0.0 (including)2.1.2 (excluding)
Php_driverMongodb*1.21.2 (excluding)
Mongo-c-driverUbuntuplucky*
Mongo-c-driverUbuntuupstream*
Php-mongodbUbuntuplucky*

Potential Mitigations

References