The KMIP response parser built into mongo binaries is overly tolerant of certain malformed packets, and may parse them into invalid objects. Later reads of this object can result in read access violations.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://jira.mongodb.org/browse/SERVER-101230 |
|
History
Tue, 04 Nov 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mongodb
Mongodb mongodb |
|
| Vendors & Products |
Mongodb
Mongodb mongodb |
Mon, 03 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 03 Nov 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The KMIP response parser built into mongo binaries is overly tolerant of certain malformed packets, and may parse them into invalid objects. Later reads of this object can result in read access violations. | |
| Title | Malformed KMIP response may result in access violation | |
| Weaknesses | CWE-754 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mongodb
Published: 2025-11-03T21:03:25.384Z
Updated: 2025-11-03T21:26:22.750Z
Reserved: 2025-11-03T20:49:39.746Z
Link: CVE-2025-12657
Updated: 2025-11-03T21:26:17.890Z
Status : Awaiting Analysis
Published: 2025-11-03T21:18:50.400
Modified: 2025-11-04T15:41:31.450
Link: CVE-2025-12657
No data.