Impact
The BSON buffer-reservation API in the MongoDB C Driver reserves memory based on a length supplied by applications. The API accepts lengths smaller than the five-byte BSON minimum. Subsequent append or comparison operations perform unsigned length calculations that underflow when the reserved length is undersized, allowing reads or writes beyond the intended document buffer. An actor who can influence the length passed to bson_reserve_buffer can cause the driver, and consequently the hosting application, to terminate or corrupt adjacent memory. This can lead to a denial‑of‑service condition and could leak or overwrite data in nearby memory, potentially exposing sensitive information or altering program state.
Affected Systems
The vulnerability affects MongoDB's official C Driver. Specific product versions are not listed in the advisory; however, any installation of the C Driver that uses the bson_reserve_buffer function without input validation is susceptible.
Risk and Exploitability
The CVSS score of 5.9 indicates a medium severity. The EPSS score is not available, and the vulnerability is not currently listed in CISA's KEV catalog, suggesting no known active exploitation. Exploitation would require an application capable of supplying an undersized length argument to bson_reserve_buffer followed by an append or comparison operation, implying a local or embedded attacker with control over driver usage. The risk thus depends on the attack surface of the application and whether it receives untrusted input that could influence the buffer‑reservation length.
OpenCVE Enrichment