[ Reason ]
Address the following issue:
* Fix CVE-2026-81524: validate db and collection names
[ Impact ]
Without this fix, users and applications integrating libmongocrypt
components may be vulnerable to potential information modification or
disclosure.
[ Tests ]
The affected/changed code went through upstream code reviews. Also,
accompanying unit tests were implemented and executed in upstream's
extensive CI environment.
[ Risks ]
Code changes are minimal (to the extent possible), extensively
reviewed/tested, and low risk. There are no work arounds.
[ Checklist ]
[x] *all* changes are documented in the d/changelog
[x] I reviewed all changes and I approve them
[x] attach debdiff against the package in (old)stable
[x] the issue is verified as fixed in unstable
[ Changes ]
Backport the following upstream change:
https://github.com/mongodb/mongo-c-driver/commit/81d0f794d07224c53f815ceb59daed28103dcf3d
[ Other info ]
N/A
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEIYZ1DR4ae5UL01q7ldFmTdL1kUIFAmqTA6MACgkQldFmTdL1
kUL9OA/9H4GmIrMIkngE2ZATKuHBXhlCv+5SnWQy2HB4zi+rFHn3sEg0eNfXTR7w
qKRxWfD/XJsMU1owt9wtVj79bP+m/AAaNMgbjrqm0HT6eGG6npJwiCISH1WsBysb
U1EDRu2IgS06SaVsk2+MWONdP6K5jhQgv1s/VgPSrRjdN9y2rP2l+B1GKV+7w34f
c0Q+Q+YNfn+B0N89Xq0UN3ALse+EigXIyv6Li9nb9KjOk4FQKuEVzMMDW6ar6xeI
CsGTTGvGMsrBYCliEDOF3dNFhgKosv8JNgGs2Vbtq2IgItNQZHOeIw+z7mRM0ew1
JzSsf8LrCboM9zF9gaFsufkDcEWRGsaeHb2nG/cWzo5HQEZ4epYrReu1I3yrOPpX
rKtAz6aW9E4PFdJ1j4YME9Se5vLzRtyzFEe9Pg0xGznTx1l30OsbV0pintbwJwm8
DQKb2479hcAHhczoZhAdm1cO8JH5cDJxOySxaD5LPbtGiGIY2oia2CTzt7mqQklc
E322eFR8V7iMUsi11srb3HTyYWn/3vq72BJJBONZ5NBXFLQp1HgjcgNgQH8O7hSZ
jBTxt3UVmA6affa6j4MY/J5aBfbleDD/eixW7hBhlVBMI91b46mgFM76+XaMFqyR
zTla4LhLwYqigsWbqO2X4rEuBpiM1Q/ItytI7ikRPqBcP6yNqOo=
=cqRe
-----END PGP SIGNATURE-----