Vulnerabilidades publicadas recientemente en el software que administramos a diario. La lista está filtrada: solo aparece lo que afecta a servidores en producción, no el catálogo completo de CVE.
| CVE | Severidad | Software | Resumen | Corregido en | Publicado |
|---|---|---|---|---|---|
| CVE-2026-54874 | Alta 7.5 | OpenSSL | Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself… | Debian:13: 3.5.7-1~deb13u2Ubuntu:14.04: 1.0.1f-1ubuntu2.27+esm16Ubuntu:16.04: 1.0.2g-1ubuntu4.20+esm18Ubuntu:18.04: 1.1.1-1ubuntu2.1~18.04.23+esm10Ubuntu:20.04: 1.1.1f-1ubuntu2.24+esm5Ubuntu:22.04: 3.0.2-0ubuntu1.29Ubuntu:24.04: 3.0.13-0ubuntu3.15Ubuntu:26.04: 3.5.5-1ubuntu3.4Ubuntu:FIPS-updates:24.04: 3.0.13-0ubuntu3.15+Fips1 |
2026-08-25 |
| CVE-2026-63072 | Alta 7.5 | OpenSSL | Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can… | Debian:13: 3.5.7-1~deb13u2Ubuntu:14.04: 1.0.1f-1ubuntu2.27+esm16Ubuntu:16.04: 1.0.2g-1ubuntu4.20+esm18Ubuntu:18.04: 1.1.1-1ubuntu2.1~18.04.23+esm10Ubuntu:20.04: 1.1.1f-1ubuntu2.24+esm5Ubuntu:22.04: 3.0.2-0ubuntu1.29Ubuntu:24.04: 3.0.13-0ubuntu3.15Ubuntu:26.04: 3.5.5-1ubuntu3.4Ubuntu:FIPS-updates:24.04: 3.0.13-0ubuntu3.15+Fips1 |
2026-08-25 |
| CVE-2026-63076 | Alta 7.5 | OpenSSL | Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before… | Debian:13: 3.5.7-1~deb13u2Ubuntu:22.04: 3.0.2-0ubuntu1.29Ubuntu:24.04: 3.0.13-0ubuntu3.15Ubuntu:26.04: 3.5.5-1ubuntu3.4Ubuntu:FIPS-updates:24.04: 3.0.13-0ubuntu3.15+Fips1 |
2026-08-25 |
| CVE-2026-14662 | Alta 8.8 | PostgreSQL | Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation… | Debian:12: 15.19-0+deb12u1Debian:13: 17.11-0+deb13u1Debian:14: 18.6-1Ubuntu:22.04: 14.24-0ubuntu0.22.04.1Ubuntu:24.04: 16.15-0ubuntu0.24.04.1Ubuntu:26.04: 18.6-0ubuntu0.26.04.1 |
2026-08-13 |
| CVE-2026-14664 | Alta 8.8 | PostgreSQL | Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that… | Debian:12: 15.19-0+deb12u1Debian:13: 17.11-0+deb13u1Debian:14: 18.6-1Ubuntu:22.04: 14.24-0ubuntu0.22.04.1Ubuntu:24.04: 16.15-0ubuntu0.24.04.1Ubuntu:26.04: 18.6-0ubuntu0.26.04.1 |
2026-08-13 |
| CVE-2026-14668 | Alta 8.1 | PostgreSQL | Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an… | Debian:12: 15.19-0+deb12u1Debian:13: 17.11-0+deb13u1Debian:14: 18.6-1Ubuntu:22.04: 14.24-0ubuntu0.22.04.1Ubuntu:24.04: 16.15-0ubuntu0.24.04.1Ubuntu:26.04: 18.6-0ubuntu0.26.04.1 |
2026-08-13 |
| CVE-2026-14669 | Alta 8.8 | PostgreSQL | Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running… | Debian:12: 15.19-0+deb12u1Debian:13: 17.11-0+deb13u1Debian:14: 18.6-1Ubuntu:22.04: 14.24-0ubuntu0.22.04.1Ubuntu:24.04: 16.15-0ubuntu0.24.04.1Ubuntu:26.04: 18.6-0ubuntu0.26.04.1 |
2026-08-13 |
| CVE-2026-14670 | Alta 8.8 | PostgreSQL | Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user running the… | Debian:12: 15.19-0+deb12u1Debian:13: 17.11-0+deb13u1Debian:14: 18.6-1Ubuntu:22.04: 14.24-0ubuntu0.22.04.1Ubuntu:24.04: 16.15-0ubuntu0.24.04.1Ubuntu:26.04: 18.6-0ubuntu0.26.04.1 |
2026-08-13 |
| CVE-2026-14671 | Alta 8.8 | PostgreSQL | Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating system user running the database. The fix for… | Debian:12: 15.19-0+deb12u1Debian:13: 17.11-0+deb13u1Debian:14: 18.6-1Ubuntu:22.04: 14.24-0ubuntu0.22.04.1Ubuntu:24.04: 16.15-0ubuntu0.24.04.1Ubuntu:26.04: 18.6-0ubuntu0.26.04.1 |
2026-08-13 |
| CVE-2026-14677 | Alta 8.8 | PostgreSQL | Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to undersize an allocation and write… | Debian:12: 15.19-0+deb12u1Debian:13: 17.11-0+deb13u1Debian:14: 18.6-1Ubuntu:22.04: 14.24-0ubuntu0.22.04.1Ubuntu:24.04: 16.15-0ubuntu0.24.04.1Ubuntu:26.04: 18.6-0ubuntu0.26.04.1 |
2026-08-13 |
| CVE-2026-14679 | Alta 8.2 | PostgreSQL | Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count. The attack can write… | Debian:12: 15.19-0+deb12u1Debian:13: 17.11-0+deb13u1Debian:14: 18.6-1Ubuntu:22.04: 14.24-0ubuntu0.22.04.1Ubuntu:24.04: 16.15-0ubuntu0.24.04.1Ubuntu:26.04: 18.6-0ubuntu0.26.04.1 |
2026-08-13 |
| CVE-2026-14680 | Alta 8.8 | PostgreSQL | Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via… | Debian:12: 15.19-0+deb12u1Debian:13: 17.11-0+deb13u1Debian:14: 18.6-1Ubuntu:22.04: 14.24-0ubuntu0.22.04.1Ubuntu:24.04: 16.15-0ubuntu0.24.04.1Ubuntu:26.04: 18.6-0ubuntu0.26.04.1 |
2026-08-13 |
| CVE-2026-15741 | Alta 8.8 | PostgreSQL | SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect… | Debian:12: 15.19-0+deb12u1Debian:13: 17.11-0+deb13u1Debian:14: 18.6-1Ubuntu:22.04: 14.24-0ubuntu0.22.04.1Ubuntu:24.04: 16.15-0ubuntu0.24.04.1Ubuntu:26.04: 18.6-0ubuntu0.26.04.1 |
2026-08-13 |
| CVE-2026-15742 | Alta 8.8 | PostgreSQL | Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system… | Debian:12: 15.19-0+deb12u1Debian:13: 17.11-0+deb13u1Debian:14: 18.6-1Ubuntu:22.04: 14.24-0ubuntu0.22.04.1Ubuntu:24.04: 16.15-0ubuntu0.24.04.1Ubuntu:26.04: 18.6-0ubuntu0.26.04.1 |
2026-08-13 |
| CVE-2026-16239 | Alta 8.8 | PostgreSQL | Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via… | Debian:12: 15.19-0+deb12u1Debian:13: 17.11-0+deb13u1Debian:14: 18.6-1Ubuntu:22.04: 14.24-0ubuntu0.22.04.1Ubuntu:24.04: 16.15-0ubuntu0.24.04.1Ubuntu:26.04: 18.6-0ubuntu0.26.04.1 |
2026-08-13 |
| CVE-2026-18408 | Alta 8.8 | PostgreSQL | Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the… | Debian:12: 15.19-0+deb12u1Debian:13: 17.11-0+deb13u1Debian:14: 18.6-1Ubuntu:22.04: 14.24-0ubuntu0.22.04.1Ubuntu:24.04: 16.15-0ubuntu0.24.04.1Ubuntu:26.04: 18.6-0ubuntu0.26.04.1 |
2026-08-13 |
| CVE-2026-19385 | Alta 8.8 | PostgreSQL | Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system user… | Debian:12: 15.19-0+deb12u1Debian:13: 17.11-0+deb13u1Debian:14: 18.6-1Ubuntu:22.04: 14.24-0ubuntu0.22.04.1Ubuntu:24.04: 16.15-0ubuntu0.24.04.1Ubuntu:26.04: 18.6-0ubuntu0.26.04.1 |
2026-08-13 |
| CVE-2026-6464 | Alta 8.1 | PostgreSQL | Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If… | Debian:12: 15.19-0+deb12u1Debian:13: 17.11-0+deb13u1Debian:14: 18.6-1Ubuntu:22.04: 14.24-0ubuntu0.22.04.1Ubuntu:24.04: 16.15-0ubuntu0.24.04.1Ubuntu:26.04: 18.6-0ubuntu0.26.04.1 |
2026-08-13 |
| CVE-2026-6471 | Alta 7.2 | PostgreSQL | Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system… | Debian:12: 15.19-0+deb12u1Debian:13: 17.11-0+deb13u1Debian:14: 18.6-1Ubuntu:22.04: 14.24-0ubuntu0.22.04.1Ubuntu:24.04: 16.15-0ubuntu0.24.04.1Ubuntu:26.04: 18.6-0ubuntu0.26.04.1 |
2026-08-13 |
| CVE-2026-63074 | Media 5.9 | OpenSSL | Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them… | Debian:13: 3.5.7-1~deb13u2Ubuntu:22.04: 3.0.2-0ubuntu1.29Ubuntu:24.04: 3.0.13-0ubuntu3.15Ubuntu:26.04: 3.5.5-1ubuntu3.4Ubuntu:FIPS-updates:24.04: 3.0.13-0ubuntu3.15+Fips1 |
2026-08-25 |
| CVE-2026-14663 | Media 6.5 | PostgreSQL | Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext. The OpenSSL… | Debian:12: 15.19-0+deb12u1Debian:13: 17.11-0+deb13u1Debian:14: 18.6-1Ubuntu:22.04: 14.24-0ubuntu0.22.04.1Ubuntu:24.04: 16.15-0ubuntu0.24.04.1Ubuntu:26.04: 18.6-0ubuntu0.26.04.1 |
2026-08-13 |
| CVE-2026-14666 | Media 4.2 | PostgreSQL | Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level… | Debian:12: 15.19-0+deb12u1Debian:13: 17.11-0+deb13u1Debian:14: 18.6-1Ubuntu:22.04: 14.24-0ubuntu0.22.04.1Ubuntu:24.04: 16.15-0ubuntu0.24.04.1Ubuntu:26.04: 18.6-0ubuntu0.26.04.1 |
2026-08-13 |
| CVE-2026-14678 | Media 4.3 | PostgreSQL | Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. This might allow a table maintainer to infer limited memory… | Debian:12: 15.19-0+deb12u1Debian:13: 17.11-0+deb13u1Debian:14: 18.6-1Ubuntu:22.04: 14.24-0ubuntu0.22.04.1Ubuntu:24.04: 16.15-0ubuntu0.24.04.1Ubuntu:26.04: 18.6-0ubuntu0.26.04.1 |
2026-08-13 |
| CVE-2026-18024 | Media 4.3 | PostgreSQL | Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value… | Debian:12: 15.19-0+deb12u1Debian:13: 17.11-0+deb13u1Debian:14: 18.6-1Ubuntu:22.04: 14.24-0ubuntu0.22.04.1Ubuntu:24.04: 16.15-0ubuntu0.24.04.1Ubuntu:26.04: 18.6-0ubuntu0.26.04.1 |
2026-08-13 |
| CVE-2026-6470 | Media 4.3 | PostgreSQL | Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a… | Debian:12: 15.19-0+deb12u1Debian:13: 17.11-0+deb13u1Debian:14: 18.6-1Ubuntu:22.04: 14.24-0ubuntu0.22.04.1Ubuntu:24.04: 16.15-0ubuntu0.24.04.1Ubuntu:26.04: 18.6-0ubuntu0.26.04.1 |
2026-08-13 |
| CVE-2026-14672 | Media 5.3 | PostgreSQL | Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence of a user via observing the SCRAM… | Ubuntu:24.04: 16.15-0ubuntu0.24.04.1Ubuntu:26.04: 18.6-0ubuntu0.26.04.1 |
2026-08-13 |
| CVE-2026-73282 | Media 4.8 | OpenSSH | In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent. | Sin parche aún | 2026-08-11 |
| CVE-2026-15059 | Media 5.5 | systemd | Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation. | Debian:14: 261~rc3-1Ubuntu:22.04: 249.11-0ubuntu3.22Ubuntu:24.04: 255.4-1ubuntu8.17Ubuntu:26.04: 259.5-0ubuntu3.4 |
2026-08-10 |
| CVE-2026-16742 | Media 6.7 | systemd | systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user | Debian:14: 261.2-1Ubuntu:22.04: 249.11-0ubuntu3.22Ubuntu:24.04: 255.4-1ubuntu8.17Ubuntu:26.04: 259.5-0ubuntu3.4 |
2026-08-10 |
| CVE-2026-14673 | Baja 3.8 | PostgreSQL | Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression… | Debian:12: 15.19-0+deb12u1Debian:13: 17.11-0+deb13u1Debian:14: 18.6-1Ubuntu:22.04: 14.24-0ubuntu0.22.04.1Ubuntu:24.04: 16.15-0ubuntu0.24.04.1Ubuntu:26.04: 18.6-0ubuntu0.26.04.1 |
2026-08-13 |
| CVE-2026-16241 | Baja 3.8 | PostgreSQL | Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea… | Debian:12: 15.19-0+deb12u1Debian:13: 17.11-0+deb13u1Debian:14: 18.6-1Ubuntu:22.04: 14.24-0ubuntu0.22.04.1Ubuntu:24.04: 16.15-0ubuntu0.24.04.1Ubuntu:26.04: 18.6-0ubuntu0.26.04.1 |
2026-08-13 |
| CVE-2026-6469 | Baja 3.8 | PostgreSQL | Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This… | Debian:12: 15.19-0+deb12u1Debian:13: 17.11-0+deb13u1Debian:14: 18.6-1Ubuntu:22.04: 14.24-0ubuntu0.22.04.1Ubuntu:24.04: 16.15-0ubuntu0.24.04.1Ubuntu:26.04: 18.6-0ubuntu0.26.04.1 |
2026-08-13 |
| CVE-2026-73281 | Baja 3.5 | OpenSSH | In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use… | Sin parche aún | 2026-08-11 |
| CVE-2026-73283 | Baja 2.5 | OpenSSH | In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not. | Sin parche aún | 2026-08-11 |
| CVE-2026-13204 | Sin clasificar | BIND | bind9 vulnerability | Ubuntu:22.04: 1:9.18.39-0ubuntu0.22.04.6Ubuntu:24.04: 1:9.18.39-0ubuntu0.24.04.7Ubuntu:26.04: 1:9.20.24-1ubuntu0.3 |
2026-08-31 |
| CVE-2025-68263 | Sin clasificar | Kernel Linux | Kernel Live Patch Security Notice | Ubuntu:16.04: 4.15.0-1195.208~16.04.1Ubuntu:18.04: 4.15.0-1195.208Ubuntu:20.04: 5.4.0-234.254Ubuntu:22.04: 5.15.0-1113.120Ubuntu:24.04: 6.8.0-1061.64Ubuntu:26.04: 7.0.0-1009.9 |
2026-08-27 |
| CVE-2026-75803 | Sin clasificar | OpenSSL | Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the… | Debian:13: 3.5.7-1~deb13u2Ubuntu:22.04: 3.0.2-0ubuntu1.29Ubuntu:24.04: 3.0.13-0ubuntu3.15Ubuntu:26.04: 3.5.5-1ubuntu3.5Ubuntu:FIPS-updates:24.04: 3.0.13-0ubuntu3.15+Fips1 |
2026-08-25 |
| CVE-2026-14456 | Sin clasificar | OpenSSL | openssl vulnerabilities | Ubuntu:22.04: 3.0.2-0ubuntu1.29Ubuntu:24.04: 3.0.13-0ubuntu3.15Ubuntu:26.04: 3.5.5-1ubuntu3.4 |
2026-08-25 |
| CVE-2025-8714 | Sin clasificar | PostgreSQL | postgresql-14, postgresql-16, postgresql-18 vulnerabilities | Ubuntu:22.04: 14.24-0ubuntu0.22.04.1Ubuntu:24.04: 16.15-0ubuntu0.24.04.1Ubuntu:26.04: 18.6-0ubuntu0.26.04.1 |
2026-08-20 |
| USN-8563-3 | Sin clasificar | Nginx | nginx vulnerability | Ubuntu:22.04: 1.18.0-6ubuntu14.19Ubuntu:24.04: 1.24.0-2ubuntu7.16Ubuntu:26.04: 1.28.3-2ubuntu1.9 |
2026-08-19 |
| USN-8563-4 | Sin clasificar | Nginx | nginx regression | Ubuntu:22.04: 1.18.0-6ubuntu14.20Ubuntu:24.04: 1.24.0-2ubuntu7.17Ubuntu:26.04: 1.28.3-2ubuntu1.10 |
2026-08-19 |
| CVE-2026-17106 | Sin clasificar | Docker | (The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, U ...) | Sin parche aún | 2026-08-19 |
| CVE-2026-10723 | Sin clasificar | BIND | bind9 vulnerabilities | Ubuntu:22.04: 1:9.18.39-0ubuntu0.22.04.5Ubuntu:24.04: 1:9.18.39-0ubuntu0.24.04.6Ubuntu:26.04: 1:9.20.24-1ubuntu0.2 |
2026-08-19 |
| USN-8626-1 | Sin clasificar | systemd | vulnerabilidades de systemd | Ubuntu:22.04: 249.11-0ubuntu3.22Ubuntu:24.04: 255.4-1ubuntu8.17Ubuntu:26.04: 259.5-0ubuntu3.4 |
2026-08-10 |
Datos de OSV.dev, que agrega los avisos de Debian, Ubuntu, Alpine y Rocky Linux. La severidad es la puntuación base CVSS 3.1 calculada a partir del vector publicado. Esta tabla se genera automáticamente y no sustituye a los avisos oficiales de tu distribución.
Ningún aviso coincide con esos filtros.
El servicio que administramos en la práctica, no todo el catálogo: Kernel Linux, systemd, OpenSSH y OpenSSL como base; Nginx y Apache como servidores web; PostgreSQL y MariaDB como bases de datos; Docker, containerd y Kubernetes en contenedores; y PHP, Postfix y BIND. Se consulta sobre Debian 12, Ubuntu 24.04 y Alpine 3.20.
Todo lo que no llega a un servidor en producción: escritorio, navegadores, aplicaciones de usuario y hardware de consumo. Una lista que lo incluyera todo sería más larga y menos útil, porque obligaría a filtrar a mano lo que aquí ya viene filtrado.
La tabla se regenera automáticamente y ninguna parte de ella la redacta un modelo de lenguaje: son datos copiados de su fuente. Para decidir qué hacer con un aviso concreto, la referencia sigue siendo el aviso oficial de tu distribución, enlazado en cada fila.
Recopilamos estos avisos a diario. Puedes seguirlos por RSS en tu lector habitual, o suscribirte solo a los de un software o una distribución concretos desde su página.
Suscribirse por RSSRevisar avisos es la parte fácil. Lo que cuesta es decidir qué urge, probarlo y aplicarlo sin cortar el servicio. Si eso hoy no lo lleva nadie, hablamos.
Soporte Linux y DevOps en español