Impact
A missing lower‑bound check in libbson’s bson_new_from_buffer() lets an attacker supply a zero‑length BSON prefix. The function reads a 32‑bit length field without ensuring it is at least the minimum BSON size of five bytes, causing an integer underflow. This underflow causes the null‑terminator test to wrap to UINT32_MAX and results in a heap out‑of‑bounds read that crashes the process, creating a denial of service condition.
Affected Systems
MongoDB Inc. C Driver is affected. Specific version information is not provided in the advisory, so any deployment using the vulnerable libbson component is potentially impacted until a patched build is applied.
Risk and Exploitability
The CVSS score is 6.9, indicating moderate severity. The EPSS score is represented as less than 1%, which denotes a very low, but non‑zero, likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. If an application can receive uncontrolled BSON data from an external source, an attacker could construct a payload with a zero‑length prefix and trigger the crash. The attack vector is inferred to be through untrusted input to the API, potentially enabling remote denial of service if the target processes external data.
OpenCVE Enrichment