The bson_strfreev function in the MongoDB C driver library may be susceptible to an integer overflow where the function will try to free memory at a negative offset. This may result in memory corruption. This issue affected libbson versions prior to 1.26.2
https://lists.debian.org/debian-lts-announce/2025/05/msg00027.html
https://lists.debian.org/debian-lts-announce/2025/05/msg00012.html