BIND
bind9 vulnerability
Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
Vulnerabilidades recientes que afectan a Ubuntu 24.04, con la versión del paquete que las corrige. Ahora mismo seguimos 98 avisos, 55 con versión corregida publicada.
BIND
bind9 vulnerability
Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
Kernel Linux
Kernel Live Patch Security Notice
Corregida en Ubuntu 16.04, Ubuntu 18.04, Ubuntu 20.04, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
OpenSSL
openssl vulnerabilities
Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
OpenSSL
Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires. Impact summary: A peer can use a…
Corregida en Debian 13, Ubuntu 14.04, Ubuntu 16.04, Ubuntu 18.04, Ubuntu 20.04, Ubuntu 22.04, Ubuntu 24.04, Ubuntu 26.04 y Ubuntu FIPS-updates 24.04.
OpenSSL
Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that…
Corregida en Debian 13, Ubuntu 14.04, Ubuntu 16.04, Ubuntu 18.04, Ubuntu 20.04, Ubuntu 22.04, Ubuntu 24.04, Ubuntu 26.04 y Ubuntu FIPS-updates 24.04.
OpenSSL
Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid). If a…
Corregida en Debian 13, Ubuntu 22.04, Ubuntu 24.04, Ubuntu 26.04 y Ubuntu FIPS-updates 24.04.
OpenSSL
Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted…
Corregida en Debian 13, Ubuntu 22.04, Ubuntu 24.04, Ubuntu 26.04 y Ubuntu FIPS-updates 24.04.
OpenSSL
Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the…
Corregida en Debian 13, Ubuntu 22.04, Ubuntu 24.04, Ubuntu 26.04 y Ubuntu FIPS-updates 24.04.
PostgreSQL
postgresql-14, postgresql-16, postgresql-18 vulnerabilities
Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
BIND
bind9 vulnerabilities
Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
Docker
(The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, U ...)
Sin parche todavía.
Nginx
nginx vulnerability
Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
Nginx
nginx regression
Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext. The OpenSSL version and OpenSSL configuration determine…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation. This…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level security policies after those changes…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user running the database, via a crafted function body…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating system user running the database. The fix for this emerged as a non-security bug…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence of a user via observing the SCRAM iteration count. This requires the probed…
Corregida en Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array…
Sin parche todavía.
PostgreSQL
Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to undersize an allocation and write out-of-bounds via crafted function bodies. This…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. This might allow a table maintainer to infer limited memory values, via the lossy signal of index…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count. The attack can write only 0x0 and 0x1 bytes. Versions before…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that…
Sin parche todavía.
PostgreSQL
SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the operating system user running the database, via conflation of range and multirange…
Sin parche todavía.
PostgreSQL
Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via re-creation of a cursor or other portal with…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix. The…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value. This is the same class of defect that…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system user running pg_dump, via a crafted transform…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
PostgreSQL
Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
OpenSSH
In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction…
Sin parche todavía.
OpenSSH
In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.
Sin parche todavía.
OpenSSH
In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.
Sin parche todavía.
systemd
Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation.
Corregida en Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
systemd
systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user
Corregida en Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
systemd
vulnerabilidades de systemd
Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
OpenSSL
Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries. Impact…
Sin parche todavía.
PHP
El escapado incorrecto de barras invertidas en parámetros proporcionados por el atacante permitiría una inyección SQL trivial en versiones de PHP desde 8.2.* antes de 8.2.33, desde 8.3.* antes de…
Corregida en Debian 11, Debian 12, Debian 13 y Debian 14.
PHP
Entradas proporcionadas por el atacante a bccomp() podrían provocar una escritura fuera de límites con corrupción de stack y heap en versiones de PHP desde 8.4.* antes de 8.4.24 y desde 8.5.* antes…
Sin parche todavía.
PHP
Los enlaces simbólicos circulares en archivos phar podrían provocar una recursión sin límite, agotando el stack de C y provocando el bloqueo del proceso PHP, en versiones de PHP desde 8.2.* antes de…
Corregida en Debian 11, Debian 12, Debian 13 y Debian 14.
OpenSSL
vulnerabilidad de openssl
Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
Kernel Linux
En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: net: nexthop: Aumentar el peso a u16 En redes CLOS, a medida que se producen fallos de enlace en varios puntos de la red, los pesos…
Sin parche todavía.
BIND
Si BIND encuentra una estructura de datos inválida particular en un registro DNS, aceptará los datos inválidos, y posteriormente puede abortar y cerrarse. BIND primero necesitará almacenar un…
Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
BIND
Un atacante que sepa (o adivine) que un resolutor usa RPZ con políticas CNAME comodín puede crear nombres de consulta lo suficientemente largos como para provocar una condición de error NAMETOOLONG…
Corregida en Debian 11, Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
BIND
Un resolutor validador de DNSSEC que esté bajo un ataque de subdominios aleatorios contra una zona firmada con DNSSEC puede sufrir un uso descontrolado de memoria. El atacante necesita ser capaz de…
Corregida en Debian 11, Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
BIND
Es posible que la zona de un atacante responda a una consulta con un RRSIG que tenga un número de etiquetas menor que la zona en la que está contenido el RRSIG. Esto hace que `named` produzca un…
Corregida en Debian 11, Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
BIND
El problema es una terminación inesperada del programa basada en el orden y/o el contenido específico en respuestas a consultas de registros CNAME o DNAME, y A. Específicamente, si un cliente…
Corregida en Debian 11, Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
BIND
El resolutor de BIND acepta registros NSEC firmados válidamente donde el campo "Next Domain Name" apunta fuera de la zona del firmante. Este problema afecta a BIND 9 versiones 9.11.0 a 9.18.50…
Corregida en Debian 11, Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
Docker
Un mensaje manipulado en la API de compilación de bajo nivel de BuildKit puede usarse para eliminar el contenido del directorio /tmp. La acción que normalmente se puede usar para eliminar archivos…
Sin parche todavía.
Docker
Un cliente o frontend malicioso de BuildKit podría crear una solicitud que podría provocar que el daemon de BuildKit se bloquee con un panic.
Sin parche todavía.
Docker
Los frontends o clientes personalizados de BuildKit que usan la API de bajo nivel sin procesar pueden establecer git.checkoutbundle=true al hacer checkout de fuentes Git. Si la fuente Git es…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: DDL). Las versiones compatibles afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Optimizer). Las versiones compatibles afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Replication). Las versiones compatibles afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: InnoDB). Las versiones compatibles afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Optimizer). Las versiones compatibles afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Optimizer). Las versiones compatibles afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Group Replication Plugin). Las versiones compatibles afectadas son MySQL Server: 8.4.0-8.4.10…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Clone Plugin). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Clone Plugin). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Clone Plugin). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Clone Plugin). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Replication). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Replication). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Group Replication Plugin). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Replication). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Replication). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Replication). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Replication). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Replication). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: X Plugin). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: X Plugin). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Replication). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Group Replication GCS). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Replication). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Replication). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Performance Schema). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Replication). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: Pluggable Auth). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10…
Sin parche todavía.
MariaDB
Vulnerabilidad en el producto MySQL Server, MySQL Cluster de Oracle MySQL (componente: Server: JSON). Las versiones soportadas que se ven afectadas son MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL…
Sin parche todavía.
PHP
vulnerabilidades de php8.1, php8.3, php8.5
Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
Nginx
vulnerabilidades de nginx
Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
Nginx
regresión de nginx
Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
Nginx
Existe una vulnerabilidad en NGINX Plus y NGINX Open Source cuando una directiva map utiliza coincidencia de expresiones regulares y una expresión de cadena hace referencia a las variables de captura…
Sin parche todavía.
Nginx
NGINX Plus y NGINX Open Source tienen una vulnerabilidad en el módulo ngx_http_ssi_module. Esta vulnerabilidad puede existir cuando se configuran Server-Side Includes (SSI), proxy_pass y la directiva…
Corregida en Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
Nginx
NGINX Plus y NGINX Open Source tienen una vulnerabilidad en el módulo ngx_http_slice_module. Cuando se configuran la directiva slice y capturas de expresión regular sin nombre, o cuando ocurre una…
Corregida en Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
OpenSSH
Vulnerabilidades de openssh
Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.
Datos de OSV.dev, publicados bajo licencia CC BY 4.0. Se recopilan a diario y se filtran al software que seguimos; así se elabora la lista.
Soporte Linux y DevOps en español