The bson_strfreev function in the MongoDB C driver library may be susceptible to an integer overflow where the function will try to free memory at a negative offset. This may result in memory corruption. This issue affected libbson versions prior to 1.26.2
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 02 Oct 2025 14:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:mongodb:libbson:*:*:*:*:*:*:*:*

cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2024-08-01T21:41:03.172Z

Reserved: 2024-06-27T08:03:35.321Z

Link: CVE-2024-6381

cve-icon Vulnrichment

Updated: 2024-08-01T21:41:03.172Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-02T18:15:03.963

Modified: 2025-10-02T13:47:04.883

Link: CVE-2024-6381

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.