Version in base suite: 1.30.4-1+deb13u3 Base version: mongo-c-driver_1.30.4-1+deb13u3 Target version: mongo-c-driver_1.30.4-1+deb13u4 Base file: /srv/ftp-master.debian.org/ftp/pool/main/m/mongo-c-driver/mongo-c-driver_1.30.4-1+deb13u3.dsc Target file: /srv/ftp-master.debian.org/policy/pool/main/m/mongo-c-driver/mongo-c-driver_1.30.4-1+deb13u4.dsc changelog | 7 +++++++ patches/0009_CVE-2026-81524.patch | 12 ++++++------ 2 files changed, 13 insertions(+), 6 deletions(-) dpkg-source: warning: cannot verify inline signature for /srv/release.debian.org/tmp/tmpqr22dxrd/mongo-c-driver_1.30.4-1+deb13u3.dsc: no acceptable signature found dpkg-source: warning: cannot verify inline signature for /srv/release.debian.org/tmp/tmpqr22dxrd/mongo-c-driver_1.30.4-1+deb13u4.dsc: no acceptable signature found diff -Nru mongo-c-driver-1.30.4/debian/changelog mongo-c-driver-1.30.4/debian/changelog --- mongo-c-driver-1.30.4/debian/changelog 2026-08-29 15:06:27.000000000 +0000 +++ mongo-c-driver-1.30.4/debian/changelog 2026-10-10 01:12:28.000000000 +0000 @@ -1,3 +1,10 @@ +mongo-c-driver (1.30.4-1+deb13u4) trixie; urgency=medium + + * Follow up to fix CVE-2026-81524: correct parameter ordering in function + definition. Thanks to Jeevan Chalke for the patch. (Closes: #1150302) + + -- Roberto C. Sanchez Fri, 09 Oct 2026 21:12:28 -0400 + mongo-c-driver (1.30.4-1+deb13u3) trixie; urgency=medium * Fix CVE-2026-81524: validate db and collection names diff -Nru mongo-c-driver-1.30.4/debian/patches/0009_CVE-2026-81524.patch mongo-c-driver-1.30.4/debian/patches/0009_CVE-2026-81524.patch --- mongo-c-driver-1.30.4/debian/patches/0009_CVE-2026-81524.patch 2026-08-29 15:06:27.000000000 +0000 +++ mongo-c-driver-1.30.4/debian/patches/0009_CVE-2026-81524.patch 2026-10-10 01:12:28.000000000 +0000 @@ -32,22 +32,22 @@ const bson_t *opts, --- a/src/libmongoc/src/mongoc/mongoc-aggregate.c +++ b/src/libmongoc/src/mongoc/mongoc-aggregate.c -@@ -185,6 +185,7 @@ - * information on how to build aggregation pipelines. +@@ -186,6 +186,7 @@ * * Parameters: -+ * @db: Database name used. Separated from @ns to validate. * @ns: Namespace (or database name for database-level aggregation). ++ * @db: Database name used. Separated from @ns to validate. * @flags: Bitwise or of mongoc_query_flags_t or 0. * @pipeline: A bson_t containing the pipeline request. @pipeline -@@ -210,6 +211,7 @@ - + * will be sent as an array type in the request. +@@ -211,6 +212,7 @@ mongoc_cursor_t * _mongoc_aggregate (mongoc_client_t *client, -+ const char *db, const char *ns, ++ const char *db, mongoc_query_flags_t flags, const bson_t *pipeline, + const bson_t *opts, @@ -237,6 +239,7 @@ BSON_ASSERT (client);