VYPR
Medium severity4.0NVD Advisory· Published Jul 2, 2024· Updated Jun 17, 2026

CVE-2024-6381

CVE-2024-6381

Description

The bson_strfreev function in the MongoDB C driver library may be susceptible to an integer overflow where the function will try to free memory at a negative offset. This may result in memory corruption. This issue affected libbson versions prior to 1.26.2

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • MongoDB/Libbson2 versions
    cpe:2.3:a:mongodb:libbson:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:mongodb:libbson:*:*:*:*:*:*:*:*range: <1.26.2
    • (no CPE)range: <1.26.2
  • MongoDB Inc/libbsonv5
    cpe:2.3:a:mongodb:libbson:0.2.0:*:*:*:*:*:*:*
    Range: 0

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.