Vulnerabilidad baja (CVSS 3.4) en PHP. Publicada el 25 de septiembre de 2026. Afecta a Debian 12 y Ubuntu 24.04. Corregida en Debian 12 (8.2.34-1~deb12u1) y Debian 13 (8.4.26-1~deb13u1). Sin parche todavía para Ubuntu 24.04.
The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough bytes for them. A malicious or compromised MySQL server can send a truncated packet and make the client read past the end of the packet buffer, which is undefined behaviour and can
Descripción original en inglés: todavía no se ha traducido.
| Distribución | Versión del paquete |
|---|---|
| Debian 12 | 8.2.34-1~deb12u1 |
| Debian 13 | 8.4.26-1~deb13u1 |
Datos de OSV.dev, publicados bajo licencia CC BY 4.0. La severidad es la puntuación base CVSS 3.1 calculada a partir del vector publicado. Esta ficha se genera automáticamente y no sustituye al aviso oficial de tu distribución; así se elabora la lista.
Soporte Linux y DevOps en español