Fin de soporte de Debian

Seguimos 3 versiones de Debian: 2 con soporte vigente y 1 fuera de soporte. La más reciente es la 13 (Trixie), publicada el 9 de agosto de 2025. La primera en quedarse sin parches es la 12, el 30 de junio de 2028.

Actualizado el 2026-09-30.

Versiones

Versión Lanzamiento Fin de soporte Soporte extendido Estado
13 (Trixie) 9 de agosto de 2025 30 de junio de 2030 30 de junio de 2035 Soportada
12 (Bookworm) 10 de junio de 2023 30 de junio de 2028 30 de junio de 2033 Soportada
11 (Bullseye) 14 de agosto de 2021 31 de agosto de 2026 30 de junio de 2031 Fin de soporte

Avisos de seguridad

Seguimos 97 avisos que afectan a Debian.

CVE-2026-42356 Baja 3.7 2026-10-01

Apache HTTP Server

Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a…

Corregida en Debian 14.

CVE-2026-42528 Media 4.3 2026-10-01

Apache HTTP Server

A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes. Users are recommended to upgrade to…

Corregida en Debian 14.

CVE-2026-46729 Alta 7.5 2026-10-01

Apache HTTP Server

NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

Corregida en Debian 14.

CVE-2026-47360 Alta 7.5 2026-10-01

Apache HTTP Server

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module.   When SessionCookieRemove changes across internal redirects, the…

Corregida en Debian 14.

CVE-2026-48005 Alta 7.5 2026-10-01

Apache HTTP Server

Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service…

Corregida en Debian 14.

CVE-2026-56153 Alta 7.5 2026-10-01

Apache HTTP Server

Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

Corregida en Debian 14.

Ver los 97 avisos de Debian

¿Te toca migrar?

Saber la fecha es la parte fácil. Planificar el salto de versión sin cortar el servicio es lo que hacemos.

Ver servicios

Fechas de endoflife.date, publicadas bajo licencia CC BY 4.0. Esta ficha se genera automáticamente y no sustituye al calendario oficial del proyecto; así se elabora la lista.