Vulnerabilidades que afectan a Debian 12

Vulnerabilidades recientes que afectan a Debian 12, con la versión del paquete que las corrige. Ahora mismo seguimos 97 avisos, 94 con versión corregida publicada.

CVE-2026-42356 Baja 3.7 2026-10-01

Apache HTTP Server

Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a…

Corregida en Debian 14.

CVE-2026-42528 Media 4.3 2026-10-01

Apache HTTP Server

A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes. Users are recommended to upgrade to…

Corregida en Debian 14.

CVE-2026-46729 Alta 7.5 2026-10-01

Apache HTTP Server

NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

Corregida en Debian 14.

CVE-2026-47360 Alta 7.5 2026-10-01

Apache HTTP Server

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module.   When SessionCookieRemove changes across internal redirects, the…

Corregida en Debian 14.

CVE-2026-48005 Alta 7.5 2026-10-01

Apache HTTP Server

Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service…

Corregida en Debian 14.

CVE-2026-56153 Alta 7.5 2026-10-01

Apache HTTP Server

Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

Corregida en Debian 14.

CVE-2026-56154 Crítica 9.8 2026-10-01

Apache HTTP Server

Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...}) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

Corregida en Debian 14.

CVE-2026-56449 Alta 7.5 2026-10-01

Apache HTTP Server

Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

Corregida en Debian 14.

CVE-2026-57941 Crítica 9.8 2026-10-01

Apache HTTP Server

Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

Corregida en Debian 14.

CVE-2026-58415 Media 5.3 2026-10-01

Apache HTTP Server

Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client to read WebDAV dead properties…

Corregida en Debian 14.

CVE-2026-59685 Alta 7.5 2026-10-01

Apache HTTP Server

Out-of-bounds Write vulnerability in Apache HTTP Server on Windows while processing paths with 8.3 names that may grow when expanded. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

Sin parche todavía.

CVE-2026-59797 Crítica 9.8 2026-10-01

Apache HTTP Server

Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

Corregida en Debian 14.

CVE-2026-63045 Alta 7.5 2026-10-01

Apache HTTP Server

Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted…

Corregida en Debian 14.

CVE-2026-63292 Alta 7.5 2026-10-01

Apache HTTP Server

Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially…

Corregida en Debian 14.

CVE-2026-63686 Alta 7.5 2026-10-01

Apache HTTP Server

A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied…

Corregida en Debian 14.

CVE-2026-63718 Alta 7.5 2026-10-01

Apache HTTP Server

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with…

Corregida en Debian 14.

CVE-2026-73636 Alta 8.1 2026-10-01

Apache HTTP Server

Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest…

Corregida en Debian 14.

CVE-2026-73637 Alta 7.3 2026-10-01

Apache HTTP Server

Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via…

Corregida en Debian 14.

CVE-2026-79768 Media 5.3 2026-10-01

Apache HTTP Server

Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd form…

Corregida en Debian 14.

CVE-2026-93546 Alta 8.8 2026-10-01

Apache HTTP Server

Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property…

Corregida en Debian 14.

CVE-2026-35189 Media 5.3 2026-09-29

OpenSSL

Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted…

Corregida en Debian 13, Ubuntu 14.04, Ubuntu 16.04, Ubuntu 18.04, Ubuntu 20.04, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-54872 Baja 3.7 2026-09-29

OpenSSL

Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret…

Corregida en Debian 13, Ubuntu 14.04, Ubuntu 16.04, Ubuntu 18.04, Ubuntu 20.04, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-75805 Media 5.3 2026-09-29

OpenSSL

Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response…

Corregida en Debian 13, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-75806 Media 5.3 2026-09-29

OpenSSL

Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV…

Corregida en Debian 13, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-77696 Baja 3.7 2026-09-29

OpenSSL

Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times may learn…

Corregida en Debian 13, Ubuntu 14.04, Ubuntu 16.04, Ubuntu 18.04, Ubuntu 20.04, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-84782 Alta 8.2 2026-09-29

OpenSSL

Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and…

Corregida en Debian 13, Ubuntu 14.04, Ubuntu 16.04, Ubuntu 18.04, Ubuntu 20.04, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2025-1218 Baja 3.4 2026-09-25

PHP

The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough bytes for them. A malicious or compromised MySQL server can send a truncated…

Corregida en Debian 12 y Debian 13.

CVE-2025-14181 Media 6.5 2026-09-25

PHP

The SOAP HTTP client guards its response buffer growth with a check that relies on signed integer overflow, which is undefined behaviour and is not guaranteed to trigger. When the check is optimised…

Corregida en Debian 12 y Debian 13.

CVE-2026-53493 Sin clasificar 2026-09-25

containerd

containerd is an open-source container runtime. Prior to versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1, a crafted OCI index graph can force very high CPU/memory usage during PullImage (before…

Sin parche todavía.

CVE-2026-6103 Media 4.3 2026-09-25

PHP

phar_tar_number() parses the octal size field of a TAR header into a uint32_t with no overflow check. The field is 11 octal digits wide and holds values up to 0x1FFFFFFFF, so a size above 0xFFFFFFFF…

Corregida en Debian 12 y Debian 13.

CVE-2026-91765 Alta 7.5 2026-09-25

PHP

cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated attacker can post a SOAP request containing tens of thousands of nested elements…

Corregida en Debian 12 y Debian 13.

CVE-2026-91766 Media 5.9 2026-09-25

PHP

When the http:// stream wrapper follows a redirect it forwards the user-supplied Authorization, Cookie and Proxy-Authorization headers unchanged, even when the redirect target is a different host, a…

Corregida en Debian 12 y Debian 13.

CVE-2026-91767 Media 6.5 2026-09-25

PHP

php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows the length argument passed to memchr() when a TLS server certificate presents a wildcard name whose literal characters are…

Corregida en Debian 12 y Debian 13.

CVE-2026-91768 Media 6.5 2026-09-25

PHP

The IPv6 branch of the FastCGI client access check compares only the first 12 bytes of a 16-byte IPv6 address, so listen.allowed_clients matches on a /96 prefix instead of the exact address. An…

Corregida en Debian 12 y Debian 13.

CVE-2026-91769 Media 4.3 2026-09-25

PHP

PHP's OpenSSL stream peer verification checks the certificate's subjectAltName entries first and, whenever no entry matches, falls back to the Common Name. RFC 6125 requires the CN to be ignored once…

Corregida en Debian 12 y Debian 13.

CVE-2026-92842 Media 5.9 2026-09-25

PHP

The convert.base64-encode, convert.quoted-printable-encode and convert.quoted-printable-decode stream filters accept a line-break-chars option whose length is tracked separately from the string…

Corregida en Debian 12 y Debian 13.

CVE-2026-93682 Media 5.8 2026-09-25

PHP

When the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redirect code reads one byte past the end of the heap buffer holding the location…

Corregida en Debian 12 y Debian 13.

CVE-2026-2270 Sin clasificar 2026-09-24

Kubernetes

Corregida en Debian 12, Debian 13 y Debian 14.

CVE-2026-19033 Media 6.5 2026-09-16

BIND

For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message with the TSIG signature arrives. This could allow an…

Corregida en Debian 13 y Debian 14.

CVE-2026-19662 Media 5.9 2026-09-16

BIND

An attacker may be able to cause a `named` resolver to abort. The attack requires inducing the victim resolver to send multiple queries for a DNSSEC-signed zone hosted by an authoritative server…

Corregida en Debian 13 y Debian 14.

CVE-2026-19666 Alta 7.5 2026-09-16

BIND

On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly. This issue…

Corregida en Debian 13 y Debian 14.

CVE-2026-19667 Alta 7.5 2026-09-16

BIND

If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in `named` results in a negative cache entry of 0 bytes. When this entry is…

Corregida en Debian 13 y Debian 14.

CVE-2026-19668 Media 5.3 2026-09-16

BIND

A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid DNSSEC record. Default limits on "max-records-per-type" and…

Corregida en Debian 13 y Debian 14.

CVE-2026-19941 Media 5.9 2026-09-16

BIND

An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an attacker at the same or an upstream level of the zone name to mask the…

Corregida en Debian 13 y Debian 14.

CVE-2026-75029 Media 5.3 2026-09-16

BIND

In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOA record). If the RDATA is the same on all the copies, the record is appended…

Corregida en Debian 13 y Debian 14.

CVE-2026-76163 Alta 7.5 2026-09-16

BIND

If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of QTYPE TKEY which may cause an assertion failure and subsequent unexpected…

Corregida en Debian 13 y Debian 14.

CVE-2026-77119 Media 5.9 2026-09-16

BIND

A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned answer through. This issue affects BIND 9…

Corregida en Debian 13 y Debian 14.

CVE-2026-77692 Alta 7.5 2026-09-16

BIND

An attacker can cause `named` to abort by sending a crafted DNS-over-HTTPS request with a cryptographically invalid SIG(0) record, and then closing the transport connection prematurely. This issue…

Corregida en Debian 13 y Debian 14.

CVE-2026-78301 Media 5.8 2026-09-16

BIND

A malformed zone may contain an NS or DNAME node above its origin, which `named` treats as a zone cut. If an attacker inserts a malformed zone into a BIND authoritative server (e.g., via zone…

Corregida en Debian 13 y Debian 14.

CVE-2026-80274 Alta 7.5 2026-09-16

BIND

If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC at the…

Corregida en Debian 13 y Debian 14.

CVE-2026-81563 Alta 7.5 2026-09-16

BIND

A BIND resolver encountering an SVCB/HTTPS AliasMode record referencing 14 or more SVCB/HTTPS ServiceMode records may fail to properly deallocate internal resources. If this happens repeatedly…

Corregida en Debian 13 y Debian 14.

CVE-2026-81736 Alta 7.5 2026-09-16

BIND

If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the resolver will spend disproportionate CPU time constructing the response. This…

Corregida en Debian 13 y Debian 14.

CVE-2026-53495 Sin clasificar 2026-09-14

containerd

containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin enabled can indefinitely block the drainExecSyncIO goroutine in…

Sin parche todavía.

CVE-2026-54874 Alta 7.5 2026-08-25

OpenSSL

Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires. Impact summary: A peer can use a…

Corregida en Debian 13 y Debian 14.

CVE-2026-63072 Alta 7.5 2026-08-25

OpenSSL

Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that…

Corregida en Debian 13 y Debian 14.

CVE-2026-63074 Media 5.9 2026-08-25

OpenSSL

Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid). If a…

Corregida en Debian 13 y Debian 14.

CVE-2026-63076 Alta 7.5 2026-08-25

OpenSSL

Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted…

Corregida en Debian 13 y Debian 14.

CVE-2026-75803 Crítica 9.1 2026-08-25

OpenSSL

Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the…

Corregida en Debian 13 y Debian 14.

CVE-2026-14662 Alta 8.8 2026-08-13

PostgreSQL

Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted…

Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-14663 Media 6.5 2026-08-13

PostgreSQL

Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext. The OpenSSL version and OpenSSL configuration determine…

Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-14664 Alta 8.8 2026-08-13

PostgreSQL

Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation. This…

Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-14666 Media 4.2 2026-08-13

PostgreSQL

Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level security policies after those changes…

Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-14668 Alta 8.1 2026-08-13

PostgreSQL

Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a…

Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-14669 Alta 8.8 2026-08-13

PostgreSQL

Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone…

Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-14670 Alta 8.8 2026-08-13

PostgreSQL

Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user running the database, via a crafted function body…

Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-14671 Alta 8.8 2026-08-13

PostgreSQL

Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating system user running the database. The fix for this emerged as a non-security bug…

Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-14673 Baja 3.8 2026-08-13

PostgreSQL

Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path…

Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-14677 Alta 8.8 2026-08-13

PostgreSQL

Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to undersize an allocation and write out-of-bounds via crafted function bodies. This…

Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-14678 Media 4.3 2026-08-13

PostgreSQL

Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. This might allow a table maintainer to infer limited memory values, via the lossy signal of index…

Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-14679 Alta 8.2 2026-08-13

PostgreSQL

Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count. The attack can write only 0x0 and 0x1 bytes. Versions before…

Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-14680 Alta 8.8 2026-08-13

PostgreSQL

Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument…

Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-15741 Alta 8.8 2026-08-13

PostgreSQL

SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly…

Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-15742 Alta 8.8 2026-08-13

PostgreSQL

Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme…

Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-16239 Alta 8.8 2026-08-13

PostgreSQL

Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via re-creation of a cursor or other portal with…

Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-16241 Baja 3.8 2026-08-13

PostgreSQL

Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix. The…

Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-18024 Media 4.3 2026-08-13

PostgreSQL

Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value. This is the same class of defect that…

Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-18408 Alta 8.8 2026-08-13

PostgreSQL

Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running…

Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-19385 Alta 8.8 2026-08-13

PostgreSQL

Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system user running pg_dump, via a crafted transform…

Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-6464 Alta 8.1 2026-08-13

PostgreSQL

Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM…

Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-6469 Baja 3.8 2026-08-13

PostgreSQL

Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP…

Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-6470 Media 4.3 2026-08-13

PostgreSQL

Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations…

Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-6471 Alta 7.2 2026-08-13

PostgreSQL

Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice…

Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-73282 Media 4.8 2026-08-11

OpenSSH

In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.

Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-73283 Baja 2.5 2026-08-11

OpenSSH

In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.

Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-15059 Media 5.5 2026-08-10

systemd

Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation.

Corregida en Debian 14.

CVE-2026-16742 Media 6.7 2026-08-10

systemd

systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user

Corregida en Debian 14.

CVE-2026-9672 Sin clasificar 2026-07-31

PHP

Corregida en Debian 11, Debian 12, Debian 13 y Debian 14.

CVE-2026-7260 Media 5.5 2026-07-30

PHP

Los enlaces simbólicos circulares en archivos phar podrían provocar una recursión sin límite, agotando el stack de C y provocando el bloqueo del proceso PHP, en versiones de PHP desde 8.2.* antes de…

Corregida en Debian 11, Debian 12, Debian 13 y Debian 14.

CVE-2026-10822 Media 6.5 2026-07-22

BIND

Si BIND encuentra una estructura de datos inválida particular en un registro DNS, aceptará los datos inválidos, y posteriormente puede abortar y cerrarse. BIND primero necesitará almacenar un…

Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-11331 Alta 7.5 2026-07-22

BIND

Un atacante que sepa (o adivine) que un resolutor usa RPZ con políticas CNAME comodín puede crear nombres de consulta lo suficientemente largos como para provocar una condición de error NAMETOOLONG…

Corregida en Debian 11, Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-11605 Alta 7.5 2026-07-22

BIND

El problema es una vulnerabilidad de agotamiento de recursos asociada a la validación DNSSEC. BIND siempre valida todos los registros RRSIG de una respuesta, incluso si no son estrictamente…

Corregida en Debian 11, Debian 12, Debian 13 y Debian 14.

CVE-2026-11622 Alta 7.5 2026-07-22

BIND

Un resolutor validador de DNSSEC que esté bajo un ataque de subdominios aleatorios contra una zona firmada con DNSSEC puede sufrir un uso descontrolado de memoria. El atacante necesita ser capaz de…

Corregida en Debian 11, Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-11721 Alta 7.5 2026-07-22

BIND

Es posible que la zona de un atacante responda a una consulta con un RRSIG que tenga un número de etiquetas menor que la zona en la que está contenido el RRSIG. Esto hace que `named` produzca un…

Corregida en Debian 11, Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-12617 Alta 7.5 2026-07-22

BIND

El problema es una terminación inesperada del programa basada en el orden y/o el contenido específico en respuestas a consultas de registros CNAME o DNAME, y A. Específicamente, si un cliente…

Corregida en Debian 11, Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-13321 Alta 8.6 2026-07-22

BIND

El resolutor de BIND acepta registros NSEC firmados válidamente donde el campo "Next Domain Name" apunta fuera de la zona del firmante. Este problema afecta a BIND 9 versiones 9.11.0 a 9.18.50…

Corregida en Debian 11, Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-56434 Media 6.5 2026-07-15

Nginx

NGINX Plus y NGINX Open Source tienen una vulnerabilidad en el módulo ngx_http_ssi_module. Esta vulnerabilidad puede existir cuando se configuran Server-Side Includes (SSI), proxy_pass y la directiva…

Corregida en Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-60005 Alta 8.2 2026-07-15

Nginx

NGINX Plus y NGINX Open Source tienen una vulnerabilidad en el módulo ngx_http_slice_module. Cuando se configuran la directiva slice y capturas de expresión regular sin nombre, o cuando ocurre una…

Corregida en Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

Datos de OSV.dev, publicados bajo licencia CC BY 4.0. Se recopilan a diario y se filtran al software que seguimos; así se elabora la lista.