CVE Vulnerabilities

CVE-2025-12119

Expired Pointer Dereference

Published: Nov 18, 2025 | Modified: Dec 08, 2025
CVSS 3.x
3.3
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

A mongoc_bulk_operation_t may read invalid memory if large options are passed.

Weakness

The product dereferences a pointer that contains a location for memory that was previously valid, but is no longer valid.

Affected Software

Name Vendor Start Version End Version
C_driver Mongodb 1.9.0 (including) 1.30.6 (excluding)
C_driver Mongodb 2.0.0 (including) 2.1.2 (excluding)
Php_driver Mongodb * 1.21.2 (excluding)
Mongo-c-driver Ubuntu upstream *

Potential Mitigations

References