Apache HTTP Server
Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a…
Corregida en Debian 14.
Vulnerabilidades recientes que afectan a Ubuntu 24.04, con la versión del paquete que las corrige. Ahora mismo seguimos 151 avisos, 101 con versión corregida publicada.
Apache HTTP Server
Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a…
Corregida en Debian 14.
Apache HTTP Server
A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes. Users are recommended to upgrade to…
Corregida en Debian 14.
Apache HTTP Server
NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Corregida en Debian 14.
Apache HTTP Server
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module. When SessionCookieRemove changes across internal redirects, the…
Corregida en Debian 14.
Apache HTTP Server
Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service…
Corregida en Debian 14.
Apache HTTP Server
Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Corregida en Debian 14.
Apache HTTP Server
Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...}) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Corregida en Debian 14.
Apache HTTP Server
Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Corregida en Debian 14.
Apache HTTP Server
Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Corregida en Debian 14.
Apache HTTP Server
Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client to read WebDAV dead properties…
Corregida en Debian 14.
Apache HTTP Server
Out-of-bounds Write vulnerability in Apache HTTP Server on Windows while processing paths with 8.3 names that may grow when expanded. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Sin parche todavía.
Apache HTTP Server
Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
Corregida en Debian 14.
Apache HTTP Server
Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted…
Corregida en Debian 14.
Apache HTTP Server
Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially…
Corregida en Debian 14.
Apache HTTP Server
A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied…
Corregida en Debian 14.
Apache HTTP Server
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with…
Corregida en Debian 14.
Apache HTTP Server
Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest…
Corregida en Debian 14.
Apache HTTP Server
Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication state corruption via…
Corregida en Debian 14.
Apache HTTP Server
Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd form…
Corregida en Debian 14.
Apache HTTP Server
Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property…
Corregida en Debian 14.
OpenSSL
Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted…
Corregida en Debian 13, Ubuntu 14.04, Ubuntu 16.04, Ubuntu 18.04, Ubuntu 20.04, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
OpenSSL
Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret…
Corregida en Debian 13, Ubuntu 14.04, Ubuntu 16.04, Ubuntu 18.04, Ubuntu 20.04, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
OpenSSL
Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response…
Corregida en Debian 13, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
OpenSSL
Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV…
Corregida en Debian 13, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
OpenSSL
Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times may learn…
Corregida en Debian 13, Ubuntu 14.04, Ubuntu 16.04, Ubuntu 18.04, Ubuntu 20.04, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
OpenSSL
Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and…
Corregida en Debian 13, Ubuntu 14.04, Ubuntu 16.04, Ubuntu 18.04, Ubuntu 20.04, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PHP
The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough bytes for them. A malicious or compromised MySQL server can send a truncated…
Corregida en Debian 12 y Debian 13.
PHP
The SOAP HTTP client guards its response buffer growth with a check that relies on signed integer overflow, which is undefined behaviour and is not guaranteed to trigger. When the check is optimised…
Corregida en Debian 12 y Debian 13.
PHP
On Windows, PHP's filesystem and stream APIs do not reject reserved device names such as CON, PRN, AUX, NUL, COM1 to COM9, LPT1 to LPT9, CONIN$ and CONOUT$ when they appear as a component of a path…
Sin parche todavía.
containerd
containerd is an open-source container runtime. Prior to versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1, a crafted OCI index graph can force very high CPU/memory usage during PullImage (before…
Sin parche todavía.
PHP
phar_tar_number() parses the octal size field of a TAR header into a uint32_t with no overflow check. The field is 11 octal digits wide and holds values up to 0x1FFFFFFFF, so a size above 0xFFFFFFFF…
Corregida en Debian 12 y Debian 13.
PHP
cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated attacker can post a SOAP request containing tens of thousands of nested elements…
Corregida en Debian 12 y Debian 13.
PHP
When the http:// stream wrapper follows a redirect it forwards the user-supplied Authorization, Cookie and Proxy-Authorization headers unchanged, even when the redirect target is a different host, a…
Corregida en Debian 12 y Debian 13.
PHP
php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows the length argument passed to memchr() when a TLS server certificate presents a wildcard name whose literal characters are…
Corregida en Debian 12 y Debian 13.
PHP
The IPv6 branch of the FastCGI client access check compares only the first 12 bytes of a 16-byte IPv6 address, so listen.allowed_clients matches on a /96 prefix instead of the exact address. An…
Corregida en Debian 12 y Debian 13.
PHP
PHP's OpenSSL stream peer verification checks the certificate's subjectAltName entries first and, whenever no entry matches, falls back to the Common Name. RFC 6125 requires the CN to be ignored once…
Corregida en Debian 12 y Debian 13.
PHP
The convert.base64-encode, convert.quoted-printable-encode and convert.quoted-printable-decode stream filters accept a line-break-chars option whose length is tracked separately from the string…
Corregida en Debian 12 y Debian 13.
PHP
When the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redirect code reads one byte past the end of the heap buffer holding the location…
Corregida en Debian 12 y Debian 13.
PostgreSQL
pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 might allow an authenticated remote user to execute arbitrary code as the…
Sin parche todavía.
Nginx
nginx ignition is a user interface for the nginx web server. Prior to version 2.41.1, `POST /api/users/onboarding/finish` is registered as anonymous (unauthenticated) and creates a user with full…
Sin parche todavía.
Nginx
nginx ignition is a user interface for the nginx web server. In versions 2.29.0 through 2.40.0, the gin i18n middleware in nginx-ignition's API server runs in front of every HTTP request and calls…
Sin parche todavía.
Nginx
nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enabled the OTP 2FA can have their TOTP reused during the standard 30 second validity…
Sin parche todavía.
BIND
For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message with the TSIG signature arrives. This could allow an…
Corregida en Debian 13 y Debian 14.
BIND
An attacker may be able to cause a `named` resolver to abort. The attack requires inducing the victim resolver to send multiple queries for a DNSSEC-signed zone hosted by an authoritative server…
Corregida en Debian 13 y Debian 14.
BIND
On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly. This issue…
Corregida en Debian 13 y Debian 14.
BIND
If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in `named` results in a negative cache entry of 0 bytes. When this entry is…
Corregida en Debian 13 y Debian 14.
BIND
A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid DNSSEC record. Default limits on "max-records-per-type" and…
Corregida en Debian 13 y Debian 14.
BIND
An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an attacker at the same or an upstream level of the zone name to mask the…
Corregida en Debian 13 y Debian 14.
BIND
In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOA record). If the RDATA is the same on all the copies, the record is appended…
Corregida en Debian 13 y Debian 14.
BIND
If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of QTYPE TKEY which may cause an assertion failure and subsequent unexpected…
Corregida en Debian 13 y Debian 14.
BIND
A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned answer through. This issue affects BIND 9…
Corregida en Debian 13 y Debian 14.
BIND
An attacker can cause `named` to abort by sending a crafted DNS-over-HTTPS request with a cryptographically invalid SIG(0) record, and then closing the transport connection prematurely. This issue…
Corregida en Debian 13 y Debian 14.
BIND
A malformed zone may contain an NS or DNAME node above its origin, which `named` treats as a zone cut. If an attacker inserts a malformed zone into a BIND authoritative server (e.g., via zone…
Corregida en Debian 13 y Debian 14.
BIND
If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC at the…
Corregida en Debian 13 y Debian 14.
BIND
A BIND resolver encountering an SVCB/HTTPS AliasMode record referencing 14 or more SVCB/HTTPS ServiceMode records may fail to properly deallocate internal resources. If this happens repeatedly…
Corregida en Debian 13 y Debian 14.
BIND
If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the resolver will spend disproportionate CPU time constructing the response. This…
Corregida en Debian 13 y Debian 14.
Docker
The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is inside an authorized workspace, but later reconnects using the pathname. A malicious guest can replace…
Sin parche todavía.
Nginx
A security issue was fixed in nginx.
Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
containerd
containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin enabled can indefinitely block the drainExecSyncIO goroutine in…
Sin parche todavía.
PHP
php8.1, php8.3, php8.5 vulnerabilities
Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
OpenSSH
openssh vulnerabilities
Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PHP
(phpseclib is a PHP secure communications library. Prior to 3.0.57 and ...)
Sin parche todavía.
PHP
(Composer is a dependency Manager for the PHP language. From 1.0 until ...)
Sin parche todavía.
BIND
bind9 vulnerability
Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
Kernel Linux
Kernel Live Patch Security Notice
Corregida en Ubuntu 16.04, Ubuntu 18.04, Ubuntu 20.04, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
OpenSSL
openssl vulnerabilities
Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
postgresql-14, postgresql-16, postgresql-18 vulnerabilities
Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
BIND
bind9 vulnerabilities
Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
Nginx
nginx vulnerability
Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
Nginx
nginx regression
Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
Docker
The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem operations to the destination directory. The…
Sin parche todavía.
PostgreSQL
Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext. The OpenSSL version and OpenSSL configuration determine…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation. This…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level security policies after those changes…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user running the database, via a crafted function body…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating system user running the database. The fix for this emerged as a non-security bug…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence of a user via observing the SCRAM iteration count. This requires the probed…
Corregida en Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array…
Sin parche todavía.
PostgreSQL
Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to undersize an allocation and write out-of-bounds via crafted function bodies. This…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. This might allow a table maintainer to infer limited memory values, via the lossy signal of index…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count. The attack can write only 0x0 and 0x1 bytes. Versions before…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that…
Sin parche todavía.
PostgreSQL
SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the operating system user running the database, via conflation of range and multirange…
Sin parche todavía.
PostgreSQL
Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via re-creation of a cursor or other portal with…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix. The…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value. This is the same class of defect that…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system user running pg_dump, via a crafted transform…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
OpenSSH
In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.
Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
OpenSSH
In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.
Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
systemd
vulnerabilidades de systemd
Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
OpenSSL
Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries. Impact…
Sin parche todavía.
PHP
Entradas proporcionadas por el atacante a bccomp() podrían provocar una escritura fuera de límites con corrupción de stack y heap en versiones de PHP desde 8.4.* antes de 8.4.24 y desde 8.5.* antes…
Sin parche todavía.
PHP
Los enlaces simbólicos circulares en archivos phar podrían provocar una recursión sin límite, agotando el stack de C y provocando el bloqueo del proceso PHP, en versiones de PHP desde 8.2.* antes de…
Corregida en Debian 11, Debian 12, Debian 13 y Debian 14.
OpenSSL
vulnerabilidad de openssl
Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
Kernel Linux
En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: net: nexthop: Aumentar el peso a u16 En redes CLOS, a medida que se producen fallos de enlace en varios puntos de la red, los pesos…
Sin parche todavía.
BIND
Si BIND encuentra una estructura de datos inválida particular en un registro DNS, aceptará los datos inválidos, y posteriormente puede abortar y cerrarse. BIND primero necesitará almacenar un…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
BIND
Un atacante que sepa (o adivine) que un resolutor usa RPZ con políticas CNAME comodín puede crear nombres de consulta lo suficientemente largos como para provocar una condición de error NAMETOOLONG…
Corregida en Debian 11, Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
BIND
Un resolutor validador de DNSSEC que esté bajo un ataque de subdominios aleatorios contra una zona firmada con DNSSEC puede sufrir un uso descontrolado de memoria. El atacante necesita ser capaz de…
Corregida en Debian 11, Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
BIND
Es posible que la zona de un atacante responda a una consulta con un RRSIG que tenga un número de etiquetas menor que la zona en la que está contenido el RRSIG. Esto hace que `named` produzca un…
Corregida en Debian 11, Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
BIND
El problema es una terminación inesperada del programa basada en el orden y/o el contenido específico en respuestas a consultas de registros CNAME o DNAME, y A. Específicamente, si un cliente…
Corregida en Debian 11, Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
BIND
El resolutor de BIND acepta registros NSEC firmados válidamente donde el campo "Next Domain Name" apunta fuera de la zona del firmante. Este problema afecta a BIND 9 versiones 9.11.0 a 9.18.50…
Corregida en Debian 11, Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
Docker
Un mensaje manipulado en la API de compilación de bajo nivel de BuildKit puede usarse para eliminar el contenido del directorio /tmp. La acción que normalmente se puede usar para eliminar archivos…
Sin parche todavía.
Docker
Un cliente o frontend malicioso de BuildKit podría crear una solicitud que podría provocar que el daemon de BuildKit se bloquee con un panic.
Sin parche todavía.
Docker
Los frontends o clientes personalizados de BuildKit que usan la API de bajo nivel sin procesar pueden establecer git.checkoutbundle=true al hacer checkout de fuentes Git. Si la fuente Git es…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: DDL). Las versiones compatibles afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Optimizer). Las versiones compatibles afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Replication). Las versiones compatibles afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: InnoDB). Las versiones compatibles afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Optimizer). Las versiones compatibles afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Optimizer). Las versiones compatibles afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Group Replication Plugin). Las versiones compatibles afectadas son MySQL Server: 8.4.0-8.4.10…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Clone Plugin). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Clone Plugin). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Clone Plugin). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Clone Plugin). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Replication). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Replication). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Group Replication Plugin). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Replication). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Replication). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Replication). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Replication). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Replication). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: X Plugin). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: X Plugin). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Replication). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Group Replication GCS). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Replication). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Replication). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Performance Schema). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Replication). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Pluggable Auth). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: JSON). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL…
Sin parche todavía.
PHP
vulnerabilidades de php8.1, php8.3, php8.5
Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
Nginx
vulnerabilidades de nginx
Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
Nginx
regresión de nginx
Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
Nginx
NGINX Plus y NGINX Open Source tienen una vulnerabilidad en el módulo ngx_http_ssi_module. Esta vulnerabilidad puede existir cuando se configuran Server-Side Includes (SSI), proxy_pass y la directiva…
Corregida en Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
Nginx
NGINX Plus y NGINX Open Source tienen una vulnerabilidad en el módulo ngx_http_slice_module. Cuando se configuran la directiva slice y capturas de expresión regular sin nombre, o cuando ocurre una…
Corregida en Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
OpenSSH
Vulnerabilidades de openssh
Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
Datos de OSV.dev, publicados bajo licencia CC BY 4.0. Se recopilan a diario y se filtran al software que seguimos; así se elabora la lista.
Soporte Linux y DevOps en español