Vulnerability Description
The bson_string_append function in MongoDB C Driver may be vulnerable to a buffer overflow where the function might attempt to allocate too small of buffer and may lead to memory corruption of neighbouring heap memory. This issue affects libbson versions prior to 1.27.1
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://jira.mongodb.org/browse/CDRIVER-5628
- https://jira.mongodb.org/browse/CDRIVER-5628
- https://lists.debian.org/debian-lts-announce/2025/05/msg00012.html
- https://lists.debian.org/debian-lts-announce/2025/05/msg00027.html
- https://security.netapp.com/advisory/ntap-20241004-0001/
FAQ
What is CVE-2024-6383?
CVE-2024-6383 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The bson_string_append function in MongoDB C Driver may be vulnerable to a buffer overflow where the function might attempt to allocate too small of buffer and may lead to memory corruption of neighbo...
How severe is CVE-2024-6383?
CVE-2024-6383 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-6383?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.