Debian 12 (Bookworm)

Fin de soporte

Debian 12 (Bookworm) es una versión estable, publicada el 10 de junio de 2023. Dejó de recibir parches de seguridad el 11 de julio de 2026. Después hay soporte extendido hasta el 30 de junio de 2028: en Debian es la LTS que mantiene la comunidad. La última versión puntual publicada es la 12.15, del 11 de julio de 2026.

Avisos de seguridad

Seguimos 47 avisos que afectan a Debian 12.

CVE-2026-54874 Alta 7.5 2026-08-25

OpenSSL

Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires. Impact summary: A peer can use a…

Corregida en Debian 13, Ubuntu 14.04, Ubuntu 16.04, Ubuntu 18.04, Ubuntu 20.04, Ubuntu 22.04, Ubuntu 24.04, Ubuntu 26.04 y Ubuntu FIPS-updates 24.04.

CVE-2026-63072 Alta 7.5 2026-08-25

OpenSSL

Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that…

Corregida en Debian 13, Ubuntu 14.04, Ubuntu 16.04, Ubuntu 18.04, Ubuntu 20.04, Ubuntu 22.04, Ubuntu 24.04, Ubuntu 26.04 y Ubuntu FIPS-updates 24.04.

CVE-2026-63074 Media 5.9 2026-08-25

OpenSSL

Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid). If a…

Corregida en Debian 13, Ubuntu 22.04, Ubuntu 24.04, Ubuntu 26.04 y Ubuntu FIPS-updates 24.04.

CVE-2026-63076 Alta 7.5 2026-08-25

OpenSSL

Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted…

Corregida en Debian 13, Ubuntu 22.04, Ubuntu 24.04, Ubuntu 26.04 y Ubuntu FIPS-updates 24.04.

CVE-2026-75803 Sin clasificar 2026-08-25

OpenSSL

Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the…

Corregida en Debian 13, Ubuntu 22.04, Ubuntu 24.04, Ubuntu 26.04 y Ubuntu FIPS-updates 24.04.

CVE-2026-14662 Alta 8.8 2026-08-13

PostgreSQL

Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted…

Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

Ver los 47 avisos de Debian 12

Fechas de endoflife.date, publicadas bajo licencia CC BY 4.0. Esta ficha se genera automáticamente y no sustituye al calendario oficial del proyecto; así se elabora la lista.