Datos actualizados a diario

Avisos de seguridad

Vulnerabilidades publicadas recientemente en el software que administramos a diario. La lista está filtrada: solo aparece lo que afecta a servidores en producción, no el catálogo completo de CVE.

19 alta 10 media 5 baja 44 vulnerabilidades · últimos 30 días · actualizado el 2026-09-01
CVE Severidad Software Resumen Corregido en Publicado
CVE-2026-54874 Alta 7.5 OpenSSL Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself… Debian:13: 3.5.7-1~deb13u2
Ubuntu:14.04: 1.0.1f-1ubuntu2.27+esm16
Ubuntu:16.04: 1.0.2g-1ubuntu4.20+esm18
Ubuntu:18.04: 1.1.1-1ubuntu2.1~18.04.23+esm10
Ubuntu:20.04: 1.1.1f-1ubuntu2.24+esm5
Ubuntu:22.04: 3.0.2-0ubuntu1.29
Ubuntu:24.04: 3.0.13-0ubuntu3.15
Ubuntu:26.04: 3.5.5-1ubuntu3.4
Ubuntu:FIPS-updates:24.04: 3.0.13-0ubuntu3.15+Fips1
2026-08-25
CVE-2026-63072 Alta 7.5 OpenSSL Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can… Debian:13: 3.5.7-1~deb13u2
Ubuntu:14.04: 1.0.1f-1ubuntu2.27+esm16
Ubuntu:16.04: 1.0.2g-1ubuntu4.20+esm18
Ubuntu:18.04: 1.1.1-1ubuntu2.1~18.04.23+esm10
Ubuntu:20.04: 1.1.1f-1ubuntu2.24+esm5
Ubuntu:22.04: 3.0.2-0ubuntu1.29
Ubuntu:24.04: 3.0.13-0ubuntu3.15
Ubuntu:26.04: 3.5.5-1ubuntu3.4
Ubuntu:FIPS-updates:24.04: 3.0.13-0ubuntu3.15+Fips1
2026-08-25
CVE-2026-63076 Alta 7.5 OpenSSL Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before… Debian:13: 3.5.7-1~deb13u2
Ubuntu:22.04: 3.0.2-0ubuntu1.29
Ubuntu:24.04: 3.0.13-0ubuntu3.15
Ubuntu:26.04: 3.5.5-1ubuntu3.4
Ubuntu:FIPS-updates:24.04: 3.0.13-0ubuntu3.15+Fips1
2026-08-25
CVE-2026-14662 Alta 8.8 PostgreSQL Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation… Debian:12: 15.19-0+deb12u1
Debian:13: 17.11-0+deb13u1
Debian:14: 18.6-1
Ubuntu:22.04: 14.24-0ubuntu0.22.04.1
Ubuntu:24.04: 16.15-0ubuntu0.24.04.1
Ubuntu:26.04: 18.6-0ubuntu0.26.04.1
2026-08-13
CVE-2026-14664 Alta 8.8 PostgreSQL Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that… Debian:12: 15.19-0+deb12u1
Debian:13: 17.11-0+deb13u1
Debian:14: 18.6-1
Ubuntu:22.04: 14.24-0ubuntu0.22.04.1
Ubuntu:24.04: 16.15-0ubuntu0.24.04.1
Ubuntu:26.04: 18.6-0ubuntu0.26.04.1
2026-08-13
CVE-2026-14668 Alta 8.1 PostgreSQL Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an… Debian:12: 15.19-0+deb12u1
Debian:13: 17.11-0+deb13u1
Debian:14: 18.6-1
Ubuntu:22.04: 14.24-0ubuntu0.22.04.1
Ubuntu:24.04: 16.15-0ubuntu0.24.04.1
Ubuntu:26.04: 18.6-0ubuntu0.26.04.1
2026-08-13
CVE-2026-14669 Alta 8.8 PostgreSQL Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running… Debian:12: 15.19-0+deb12u1
Debian:13: 17.11-0+deb13u1
Debian:14: 18.6-1
Ubuntu:22.04: 14.24-0ubuntu0.22.04.1
Ubuntu:24.04: 16.15-0ubuntu0.24.04.1
Ubuntu:26.04: 18.6-0ubuntu0.26.04.1
2026-08-13
CVE-2026-14670 Alta 8.8 PostgreSQL Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user running the… Debian:12: 15.19-0+deb12u1
Debian:13: 17.11-0+deb13u1
Debian:14: 18.6-1
Ubuntu:22.04: 14.24-0ubuntu0.22.04.1
Ubuntu:24.04: 16.15-0ubuntu0.24.04.1
Ubuntu:26.04: 18.6-0ubuntu0.26.04.1
2026-08-13
CVE-2026-14671 Alta 8.8 PostgreSQL Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating system user running the database. The fix for… Debian:12: 15.19-0+deb12u1
Debian:13: 17.11-0+deb13u1
Debian:14: 18.6-1
Ubuntu:22.04: 14.24-0ubuntu0.22.04.1
Ubuntu:24.04: 16.15-0ubuntu0.24.04.1
Ubuntu:26.04: 18.6-0ubuntu0.26.04.1
2026-08-13
CVE-2026-14677 Alta 8.8 PostgreSQL Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to undersize an allocation and write… Debian:12: 15.19-0+deb12u1
Debian:13: 17.11-0+deb13u1
Debian:14: 18.6-1
Ubuntu:22.04: 14.24-0ubuntu0.22.04.1
Ubuntu:24.04: 16.15-0ubuntu0.24.04.1
Ubuntu:26.04: 18.6-0ubuntu0.26.04.1
2026-08-13
CVE-2026-14679 Alta 8.2 PostgreSQL Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count. The attack can write… Debian:12: 15.19-0+deb12u1
Debian:13: 17.11-0+deb13u1
Debian:14: 18.6-1
Ubuntu:22.04: 14.24-0ubuntu0.22.04.1
Ubuntu:24.04: 16.15-0ubuntu0.24.04.1
Ubuntu:26.04: 18.6-0ubuntu0.26.04.1
2026-08-13
CVE-2026-14680 Alta 8.8 PostgreSQL Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via… Debian:12: 15.19-0+deb12u1
Debian:13: 17.11-0+deb13u1
Debian:14: 18.6-1
Ubuntu:22.04: 14.24-0ubuntu0.22.04.1
Ubuntu:24.04: 16.15-0ubuntu0.24.04.1
Ubuntu:26.04: 18.6-0ubuntu0.26.04.1
2026-08-13
CVE-2026-15741 Alta 8.8 PostgreSQL SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect… Debian:12: 15.19-0+deb12u1
Debian:13: 17.11-0+deb13u1
Debian:14: 18.6-1
Ubuntu:22.04: 14.24-0ubuntu0.22.04.1
Ubuntu:24.04: 16.15-0ubuntu0.24.04.1
Ubuntu:26.04: 18.6-0ubuntu0.26.04.1
2026-08-13
CVE-2026-15742 Alta 8.8 PostgreSQL Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system… Debian:12: 15.19-0+deb12u1
Debian:13: 17.11-0+deb13u1
Debian:14: 18.6-1
Ubuntu:22.04: 14.24-0ubuntu0.22.04.1
Ubuntu:24.04: 16.15-0ubuntu0.24.04.1
Ubuntu:26.04: 18.6-0ubuntu0.26.04.1
2026-08-13
CVE-2026-16239 Alta 8.8 PostgreSQL Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via… Debian:12: 15.19-0+deb12u1
Debian:13: 17.11-0+deb13u1
Debian:14: 18.6-1
Ubuntu:22.04: 14.24-0ubuntu0.22.04.1
Ubuntu:24.04: 16.15-0ubuntu0.24.04.1
Ubuntu:26.04: 18.6-0ubuntu0.26.04.1
2026-08-13
CVE-2026-18408 Alta 8.8 PostgreSQL Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the… Debian:12: 15.19-0+deb12u1
Debian:13: 17.11-0+deb13u1
Debian:14: 18.6-1
Ubuntu:22.04: 14.24-0ubuntu0.22.04.1
Ubuntu:24.04: 16.15-0ubuntu0.24.04.1
Ubuntu:26.04: 18.6-0ubuntu0.26.04.1
2026-08-13
CVE-2026-19385 Alta 8.8 PostgreSQL Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system user… Debian:12: 15.19-0+deb12u1
Debian:13: 17.11-0+deb13u1
Debian:14: 18.6-1
Ubuntu:22.04: 14.24-0ubuntu0.22.04.1
Ubuntu:24.04: 16.15-0ubuntu0.24.04.1
Ubuntu:26.04: 18.6-0ubuntu0.26.04.1
2026-08-13
CVE-2026-6464 Alta 8.1 PostgreSQL Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If… Debian:12: 15.19-0+deb12u1
Debian:13: 17.11-0+deb13u1
Debian:14: 18.6-1
Ubuntu:22.04: 14.24-0ubuntu0.22.04.1
Ubuntu:24.04: 16.15-0ubuntu0.24.04.1
Ubuntu:26.04: 18.6-0ubuntu0.26.04.1
2026-08-13
CVE-2026-6471 Alta 7.2 PostgreSQL Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system… Debian:12: 15.19-0+deb12u1
Debian:13: 17.11-0+deb13u1
Debian:14: 18.6-1
Ubuntu:22.04: 14.24-0ubuntu0.22.04.1
Ubuntu:24.04: 16.15-0ubuntu0.24.04.1
Ubuntu:26.04: 18.6-0ubuntu0.26.04.1
2026-08-13
CVE-2026-63074 Media 5.9 OpenSSL Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them… Debian:13: 3.5.7-1~deb13u2
Ubuntu:22.04: 3.0.2-0ubuntu1.29
Ubuntu:24.04: 3.0.13-0ubuntu3.15
Ubuntu:26.04: 3.5.5-1ubuntu3.4
Ubuntu:FIPS-updates:24.04: 3.0.13-0ubuntu3.15+Fips1
2026-08-25
CVE-2026-14663 Media 6.5 PostgreSQL Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext. The OpenSSL… Debian:12: 15.19-0+deb12u1
Debian:13: 17.11-0+deb13u1
Debian:14: 18.6-1
Ubuntu:22.04: 14.24-0ubuntu0.22.04.1
Ubuntu:24.04: 16.15-0ubuntu0.24.04.1
Ubuntu:26.04: 18.6-0ubuntu0.26.04.1
2026-08-13
CVE-2026-14666 Media 4.2 PostgreSQL Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level… Debian:12: 15.19-0+deb12u1
Debian:13: 17.11-0+deb13u1
Debian:14: 18.6-1
Ubuntu:22.04: 14.24-0ubuntu0.22.04.1
Ubuntu:24.04: 16.15-0ubuntu0.24.04.1
Ubuntu:26.04: 18.6-0ubuntu0.26.04.1
2026-08-13
CVE-2026-14678 Media 4.3 PostgreSQL Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. This might allow a table maintainer to infer limited memory… Debian:12: 15.19-0+deb12u1
Debian:13: 17.11-0+deb13u1
Debian:14: 18.6-1
Ubuntu:22.04: 14.24-0ubuntu0.22.04.1
Ubuntu:24.04: 16.15-0ubuntu0.24.04.1
Ubuntu:26.04: 18.6-0ubuntu0.26.04.1
2026-08-13
CVE-2026-18024 Media 4.3 PostgreSQL Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value… Debian:12: 15.19-0+deb12u1
Debian:13: 17.11-0+deb13u1
Debian:14: 18.6-1
Ubuntu:22.04: 14.24-0ubuntu0.22.04.1
Ubuntu:24.04: 16.15-0ubuntu0.24.04.1
Ubuntu:26.04: 18.6-0ubuntu0.26.04.1
2026-08-13
CVE-2026-6470 Media 4.3 PostgreSQL Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a… Debian:12: 15.19-0+deb12u1
Debian:13: 17.11-0+deb13u1
Debian:14: 18.6-1
Ubuntu:22.04: 14.24-0ubuntu0.22.04.1
Ubuntu:24.04: 16.15-0ubuntu0.24.04.1
Ubuntu:26.04: 18.6-0ubuntu0.26.04.1
2026-08-13
CVE-2026-14672 Media 5.3 PostgreSQL Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence of a user via observing the SCRAM… Ubuntu:24.04: 16.15-0ubuntu0.24.04.1
Ubuntu:26.04: 18.6-0ubuntu0.26.04.1
2026-08-13
CVE-2026-73282 Media 4.8 OpenSSH In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent. Sin parche aún 2026-08-11
CVE-2026-15059 Media 5.5 systemd Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation. Debian:14: 261~rc3-1
Ubuntu:22.04: 249.11-0ubuntu3.22
Ubuntu:24.04: 255.4-1ubuntu8.17
Ubuntu:26.04: 259.5-0ubuntu3.4
2026-08-10
CVE-2026-16742 Media 6.7 systemd systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user Debian:14: 261.2-1
Ubuntu:22.04: 249.11-0ubuntu3.22
Ubuntu:24.04: 255.4-1ubuntu8.17
Ubuntu:26.04: 259.5-0ubuntu3.4
2026-08-10
CVE-2026-14673 Baja 3.8 PostgreSQL Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression… Debian:12: 15.19-0+deb12u1
Debian:13: 17.11-0+deb13u1
Debian:14: 18.6-1
Ubuntu:22.04: 14.24-0ubuntu0.22.04.1
Ubuntu:24.04: 16.15-0ubuntu0.24.04.1
Ubuntu:26.04: 18.6-0ubuntu0.26.04.1
2026-08-13
CVE-2026-16241 Baja 3.8 PostgreSQL Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea… Debian:12: 15.19-0+deb12u1
Debian:13: 17.11-0+deb13u1
Debian:14: 18.6-1
Ubuntu:22.04: 14.24-0ubuntu0.22.04.1
Ubuntu:24.04: 16.15-0ubuntu0.24.04.1
Ubuntu:26.04: 18.6-0ubuntu0.26.04.1
2026-08-13
CVE-2026-6469 Baja 3.8 PostgreSQL Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This… Debian:12: 15.19-0+deb12u1
Debian:13: 17.11-0+deb13u1
Debian:14: 18.6-1
Ubuntu:22.04: 14.24-0ubuntu0.22.04.1
Ubuntu:24.04: 16.15-0ubuntu0.24.04.1
Ubuntu:26.04: 18.6-0ubuntu0.26.04.1
2026-08-13
CVE-2026-73281 Baja 3.5 OpenSSH In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use… Sin parche aún 2026-08-11
CVE-2026-73283 Baja 2.5 OpenSSH In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not. Sin parche aún 2026-08-11
CVE-2026-13204 Sin clasificar BIND bind9 vulnerability Ubuntu:22.04: 1:9.18.39-0ubuntu0.22.04.6
Ubuntu:24.04: 1:9.18.39-0ubuntu0.24.04.7
Ubuntu:26.04: 1:9.20.24-1ubuntu0.3
2026-08-31
CVE-2025-68263 Sin clasificar Kernel Linux Kernel Live Patch Security Notice Ubuntu:16.04: 4.15.0-1195.208~16.04.1
Ubuntu:18.04: 4.15.0-1195.208
Ubuntu:20.04: 5.4.0-234.254
Ubuntu:22.04: 5.15.0-1113.120
Ubuntu:24.04: 6.8.0-1061.64
Ubuntu:26.04: 7.0.0-1009.9
2026-08-27
CVE-2026-75803 Sin clasificar OpenSSL Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the… Debian:13: 3.5.7-1~deb13u2
Ubuntu:22.04: 3.0.2-0ubuntu1.29
Ubuntu:24.04: 3.0.13-0ubuntu3.15
Ubuntu:26.04: 3.5.5-1ubuntu3.5
Ubuntu:FIPS-updates:24.04: 3.0.13-0ubuntu3.15+Fips1
2026-08-25
CVE-2026-14456 Sin clasificar OpenSSL openssl vulnerabilities Ubuntu:22.04: 3.0.2-0ubuntu1.29
Ubuntu:24.04: 3.0.13-0ubuntu3.15
Ubuntu:26.04: 3.5.5-1ubuntu3.4
2026-08-25
CVE-2025-8714 Sin clasificar PostgreSQL postgresql-14, postgresql-16, postgresql-18 vulnerabilities Ubuntu:22.04: 14.24-0ubuntu0.22.04.1
Ubuntu:24.04: 16.15-0ubuntu0.24.04.1
Ubuntu:26.04: 18.6-0ubuntu0.26.04.1
2026-08-20
USN-8563-3 Sin clasificar Nginx nginx vulnerability Ubuntu:22.04: 1.18.0-6ubuntu14.19
Ubuntu:24.04: 1.24.0-2ubuntu7.16
Ubuntu:26.04: 1.28.3-2ubuntu1.9
2026-08-19
USN-8563-4 Sin clasificar Nginx nginx regression Ubuntu:22.04: 1.18.0-6ubuntu14.20
Ubuntu:24.04: 1.24.0-2ubuntu7.17
Ubuntu:26.04: 1.28.3-2ubuntu1.10
2026-08-19
CVE-2026-17106 Sin clasificar Docker (The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, U ...) Sin parche aún 2026-08-19
CVE-2026-10723 Sin clasificar BIND bind9 vulnerabilities Ubuntu:22.04: 1:9.18.39-0ubuntu0.22.04.5
Ubuntu:24.04: 1:9.18.39-0ubuntu0.24.04.6
Ubuntu:26.04: 1:9.20.24-1ubuntu0.2
2026-08-19
USN-8626-1 Sin clasificar systemd vulnerabilidades de systemd Ubuntu:22.04: 249.11-0ubuntu3.22
Ubuntu:24.04: 255.4-1ubuntu8.17
Ubuntu:26.04: 259.5-0ubuntu3.4
2026-08-10

Datos de OSV.dev, que agrega los avisos de Debian, Ubuntu, Alpine y Rocky Linux. La severidad es la puntuación base CVSS 3.1 calculada a partir del vector publicado. Esta tabla se genera automáticamente y no sustituye a los avisos oficiales de tu distribución.

Buscar por software o distribución

Por software

Por distribución

Cómo se elabora esta lista

Qué software se vigila

El servicio que administramos en la práctica, no todo el catálogo: Kernel Linux, systemd, OpenSSH y OpenSSL como base; Nginx y Apache como servidores web; PostgreSQL y MariaDB como bases de datos; Docker, containerd y Kubernetes en contenedores; y PHP, Postfix y BIND. Se consulta sobre Debian 12, Ubuntu 24.04 y Alpine 3.20.

Qué queda fuera

Todo lo que no llega a un servidor en producción: escritorio, navegadores, aplicaciones de usuario y hardware de consumo. Una lista que lo incluyera todo sería más larga y menos útil, porque obligaría a filtrar a mano lo que aquí ya viene filtrado.

Cómo leer las columnas

  • Severidad es la puntuación base CVSS 3.1 calculada desde el vector publicado, no una estimación nuestra. Cuando el mismo fallo tiene vectores distintos según la distribución, se muestra el más grave.
  • Corregido en lista las versiones que ya incluyen el parche, por distribución. Que aparezca una versión de Debian 13 y no de Debian 12 significa exactamente eso: el parche existe, pero todavía no ha llegado a esa rama.
  • Sin parche aún significa que ninguna distribución ha publicado versión corregida. Son las que conviene mirar primero, porque la respuesta no es actualizar sino mitigar.

La tabla se regenera automáticamente y ninguna parte de ella la redacta un modelo de lenguaje: son datos copiados de su fuente. Para decidir qué hacer con un aviso concreto, la referencia sigue siendo el aviso oficial de tu distribución, enlazado en cada fila.

Sigue los avisos

Recopilamos estos avisos a diario. Puedes seguirlos por RSS en tu lector habitual, o suscribirte solo a los de un software o una distribución concretos desde su página.

Suscribirse por RSS

¿Quién aplica estos parches en tus servidores?

Revisar avisos es la parte fácil. Lo que cuesta es decidir qué urge, probarlo y aplicarlo sin cortar el servicio. Si eso hoy no lo lleva nadie, hablamos.