#1146079 trixie-pu: package libmongocrypt/1.13.2-1+deb13u1

#1146079#5
Date:
2026-08-29 16:04:05 UTC
From:
To:
[ Reason ]
Address the following issue:

  * Fix CVE-2026-81523: validate db and collection names

[ Impact ]
Without this fix, users and applications integrating libmongocrypt
components may be vulnerable to potential information modification or
disclosure.

[ Tests ]
The affected/changed code went through upstream code reviews. Also,
accompanying unit tests were implemented and executed in upstream's
extensive CI environment.

[ Risks ]
Code changes are minimal (to the extent possible), extensively
reviewed/tested, and low risk. There are no work arounds.

[ Checklist ]
  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in (old)stable
  [x] the issue is verified as fixed in unstable

[ Changes ]
Backport the following upstream change:
https://github.com/mongodb/libmongocrypt/commit/0f8d744a8c5e1877e40efd1c8b440e4eed1e2462

[ Other info ]
N/A
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEIYZ1DR4ae5UL01q7ldFmTdL1kUIFAmqTAvUACgkQldFmTdL1
kUKkkA//esD+6cjeZ1BQd02CK+fEKxbx0v6cAHB9BMH7193s/SWqe8f0gQo0r53h
MHMw8l49riPzr/gabY+RgV1t1t+0QOs/6DxPfneR4WHonR8RCfZfhSocQSIexUov
T9TJ3WyVAWxU401eIWhKapwDGNaszssut0kKH/Ii1kFk8cd1QMgPICz9YmFOshXk
v8lW2YGpxusqqQUSfPVJ6gJEI30VDgei8X3g8LYFdkPXJsgPlKgE+RqvmBX6kxlC
jMYpYDGN0SSYmKLvpn2QVCcPaPkcTSQQPYnVsHPcjnWG+aU6Ju+Xdpaj9EGfmIm4
mCMMw9nGff3+B9yC16ZKAz8HTEPadfBun3yzyDtabN3iUr1Fm1nNQgUGEkd8iXh4
srncjW6M1rvFZmfdgDnk0h4IWhIC8YC6T2TgtocUeur6Epq76Z46qGF51NtRPN5j
AbAXPjbx8caztIpZUzF6oQyi5FnhfpcCKjUNKSRUeb4O7w4Ojahq4xU/ZiCSr9o9
cLAiNOQGb7o5237bzOX9SNd6vJqOFzSgoOzlggTur4R9IwAcH2IAVzlkyNuxXwW6
iwTMuNkF/Z67hcgOll2bkVe6AolCrzEzGOPFrdE2uErDca6C8VKC1Y39lqSqB5Go
6NiZNDheuH4uu4ECrcbrC0CEAoDIKhDQYV4ZUh/IyhnPm9mzEfA=
=TYdC
-----END PGP SIGNATURE-----

#1146079#10
Date:
2026-09-04 08:41:56 UTC
From:
To:
package release.debian.org
tags 1146079 = trixie pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie.

Thanks for your contribution!

Upload details
==============

Package: libmongocrypt
Version: 1.13.2-1+deb13u1

Explanation: fix missing input validation issue [CVE-2026-81523]

#1146079#15
Date:
2026-09-04 08:41:56 UTC
From:
To:
package release.debian.org
tags 1146079 = trixie pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie.

Thanks for your contribution!

Upload details
==============

Package: libmongocrypt
Version: 1.13.2-1+deb13u1

Explanation: fix missing input validation issue [CVE-2026-81523]

#1146079#20
Date:
2026-09-12 08:05:41 UTC
From:
To:
This update was released as part of 13.7.