Medium severity4.0NVD Advisory· Published Jul 2, 2024· Updated Jun 17, 2026
CVE-2024-6381
CVE-2024-6381
Description
The bson_strfreev function in the MongoDB C driver library may be susceptible to an integer overflow where the function will try to free memory at a negative offset. This may result in memory corruption. This issue affected libbson versions prior to 1.26.2
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- MongoDB Inc/libbsonv5cpe:2.3:a:mongodb:libbson:0.2.0:*:*:*:*:*:*:*Range: 0
Patches
Vulnerability mechanics
References
3- jira.mongodb.org/browse/CDRIVER-5622nvdIssue TrackingVendor Advisory
- lists.debian.org/debian-lts-announce/2025/05/msg00012.htmlnvd
- lists.debian.org/debian-lts-announce/2025/05/msg00027.htmlnvd
News mentions
0No linked articles in our index yet.