[ Reason ]
Address the following issue:
* Fix CVE-2026-81523: validate db and collection names
[ Impact ]
Without this fix, users and applications integrating libmongocrypt
components may be vulnerable to potential information modification or
disclosure.
[ Tests ]
The affected/changed code went through upstream code reviews. Also,
accompanying unit tests were implemented and executed in upstream's
extensive CI environment.
[ Risks ]
Code changes are minimal (to the extent possible), extensively
reviewed/tested, and low risk. There are no work arounds.
[ Checklist ]
[x] *all* changes are documented in the d/changelog
[x] I reviewed all changes and I approve them
[x] attach debdiff against the package in (old)stable
[x] the issue is verified as fixed in unstable
[ Changes ]
Backport the following upstream change:
https://github.com/mongodb/libmongocrypt/commit/0f8d744a8c5e1877e40efd1c8b440e4eed1e2462
[ Other info ]
N/A
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEIYZ1DR4ae5UL01q7ldFmTdL1kUIFAmqTAvUACgkQldFmTdL1
kUKkkA//esD+6cjeZ1BQd02CK+fEKxbx0v6cAHB9BMH7193s/SWqe8f0gQo0r53h
MHMw8l49riPzr/gabY+RgV1t1t+0QOs/6DxPfneR4WHonR8RCfZfhSocQSIexUov
T9TJ3WyVAWxU401eIWhKapwDGNaszssut0kKH/Ii1kFk8cd1QMgPICz9YmFOshXk
v8lW2YGpxusqqQUSfPVJ6gJEI30VDgei8X3g8LYFdkPXJsgPlKgE+RqvmBX6kxlC
jMYpYDGN0SSYmKLvpn2QVCcPaPkcTSQQPYnVsHPcjnWG+aU6Ju+Xdpaj9EGfmIm4
mCMMw9nGff3+B9yC16ZKAz8HTEPadfBun3yzyDtabN3iUr1Fm1nNQgUGEkd8iXh4
srncjW6M1rvFZmfdgDnk0h4IWhIC8YC6T2TgtocUeur6Epq76Z46qGF51NtRPN5j
AbAXPjbx8caztIpZUzF6oQyi5FnhfpcCKjUNKSRUeb4O7w4Ojahq4xU/ZiCSr9o9
cLAiNOQGb7o5237bzOX9SNd6vJqOFzSgoOzlggTur4R9IwAcH2IAVzlkyNuxXwW6
iwTMuNkF/Z67hcgOll2bkVe6AolCrzEzGOPFrdE2uErDca6C8VKC1Y39lqSqB5Go
6NiZNDheuH4uu4ECrcbrC0CEAoDIKhDQYV4ZUh/IyhnPm9mzEfA=
=TYdC
-----END PGP SIGNATURE-----