Updated Debian 13: 13.7 released
September 12th, 2026
The Debian project is pleased to announce the seventh update of its
stable distribution Debian 13 (codename trixie
).
This point release mainly adds corrections for security issues,
along with a few adjustments for serious problems. Security advisories
have already been published separately and are referenced where available.
Please note that the point release does not constitute a new version of Debian
13 but only updates some of the packages included. There is
no need to throw away old trixie
media. After installation,
packages can be upgraded to the current versions using an up-to-date Debian
mirror.
Those who frequently install updates from security.debian.org won't have to update many packages, and most such updates are included in the point release.
New installation images will be available soon at the regular locations.
Upgrading an existing installation to this revision can be achieved by pointing the package management system at one of Debian's many HTTP mirrors. A comprehensive list of mirrors is available at:
Miscellaneous Bugfixes
This stable update adds a few important corrections to the following packages:
| Package | Reason |
|---|---|
| akonadi-search | Fix crash with empty input |
| alsa-lib | Fix heap overflow issue [CVE-2026-25068] |
| ansible-core | New upstream stable release; fix arbitrary code injection issue [CVE-2026-11332] |
| at-spi2-core | Fix atkversion.h header for C++ linkage |
| audit | Add support for the riscv64 architecture |
| auto-apt-proxy | Prevent apt-helper call from recursing into auto-apt-proxy; wait for network to be online |
| awffull | Fix visit / page statistics |
| base-files | Update for the point release; add AGPL-3.0, Artistic-2.0, BSL-1.0, CC-BY-3.0, CC-BY-4.0, CC-BY-SA-3.0, CC-BY-SA-4.0, GFDL-1.1 and OFL-1.1 to common-licenses |
| bash | Rebuild with updated glibc |
| bcg729 | Fix division by zero |
| bettercap | Fix mysql.server module remote DoS via crafted client handshake [CVE-2026-8276]; stop installing systemd service by default |
| bglibs | Rebuild with updated glibc |
| binwalk | Fix path traversal issue [CVE-2026-7179] |
| busybox | Rebuild with updated glibc |
| catatonit | Rebuild with updated glibc |
| cdebootstrap | Rebuild with updated glibc |
| chkrootkit | Rebuild with updated glibc |
| cinnamon | Fix download and update of spices (applets, desklets, extensions and themes) |
| condor | Rebuild with updated glibc |
| curl | Fix OpenSSL engine loading return value; remove trailing whitespaces causing test failures |
| cyrus-imapd | Allow JMAP EventSource without WebSocket/wslay; fix insufficient access check issues [CVE-2026-47084 CVE-2026-47086 CVE-2026-47087 CVE-2026-47081 CVE-2026-47089 CVE-2026-47085 CVE-2026-47083 CVE-2026-47082]; fix out of bounds read issue [CVE-2026-47088] |
| dar | Rebuild with updated glibc; rebuild with updated curl; fix glibc Built-Using regression |
| dcmtk | Fix denial of service issues [CVE-2026-35505 CVE-2026-44628 CVE-2026-50254]; fix path traversal issues [CVE-2026-50003 CVE-2026-52868] |
| debian-edu-config | New upstream stable release |
| debian-edu-install | Skip Icinga 2 IDO MySQL dbconfig setup |
| debian-installer | Bump linux ABI to 6.12.107+deb13; rebuild for the point release |
| debian-installer-netboot-images | Rebuild against proposed-updates |
| dhcpcd | Fix IPv6 Neighbor Discovery option parsing to discard advertisements with zero-length options [CVE-2026-14258] |
| dnsmasq | Fix buffer overflow issue [CVE-2026-12725]; fix out of bounds read issue [CVE-2026-12969] |
| docker.io | Rebuild with updated glibc |
| flask | Ensure Vary: Cookieis set on session access [CVE-2026-27205] |
| fluidsynth | Fix buffer overflow issues [CVE-2026-58264 CVE-2026-61714] |
| glib2.0 | Fix out of bounds access issues [CVE-2026-58010 CVE-2026-58011 CVE-2026-58012 CVE-2026-58013 CVE-2026-58014]; fix file content disclosure issue [CVE-2026-58015]; fix denial of service issue [CVE-2026-15588]; fix integer underflow issue [CVE-2026-58016]; fix out of bounds write issue [CVE-2026-16118] |
| glibc | Fix buffer overflow/underflow issues [CVE-2026-5928 CVE-2026-5450]; ensure compatibility with linux 7.0 headers |
| gnupg2 | Rebuild with updated glibc |
| goaccess | Fix out of bounds write issue [CVE-2026-54715]; fix denial of service issue [CVE-2026-55768 CVE-2026-55777] |
| gpsd | Fix gpsprof command and code injection in gnuplot script generation [CVE-2026-58459 CVE-2026-60122] |
| gzip | Fix insecure temporary file handling issue [CVE-2026-41991]; fix buffer overflow issue [CVE-2026-41992] |
| imagemagick | Fix buffer overflow issues [CVE-2026-56362 CVE-2026-56372 CVE-2026-56374 CVE-2026-61464]; fix memory leak issues [CVE-2026-56366 CVE-2026-56375 CVE-2026-61863 CVE-2026-61864 CVE-2026-61865 CVE-2026-61866 CVE-2026-61867 CVE-2026-61868 CVE-2026-61869 CVE-2026-61870 CVE-2026-61871 CVE-2026-61872]; fix use-after-free issues [CVE-2026-56373 CVE-2026-61857 CVE-2026-61860 CVE-2026-61861]; fix denial of service issue [CVE-2026-61465]; fix policy bypass issues [CVE-2026-61858 CVE-2026-61859]; fix information disclosure issue [CVE-2026-61862] |
| incus | Fix path traversal issue [CVE-2026-81500]; fix insufficent access check issue [CVE-2026-81501] |
| integrit | Rebuild with updated glibc |
| libcap2 | Rebuild with updated glibc |
| libdatetime-timezone-perl | Update to Olson 2026c; Alberta, CA permanently -06; Morocco, permanently 00 |
| libdbd-csv-perl | Fix test failure |
| libhttp-tiny-perl | Fix CRLF validation issue [CVE-2026-7010]; fix credential forwarding on redirects issue [CVE-2026-7017] |
| libio-compress-perl | Fix header parsing issue [CVE-2025-15649]; fix denial of service issue [CVE-2026-48959]; fix crash in zipdetails [CVE-2026-48961]; fix code execution issue [CVE-2026-48962] |
| libmodule-cpants-analyse-perl | Fix interoperability with Archive::Tar >= 3.08 |
| libmongocrypt | Fix missing input validation issue [CVE-2026-81523] |
| libnet-cidr-set-perl | Fix IPv4/IPv6 CIDR parsing validation [CVE-2026-49940 CVE-2026-49941 CVE-2026-49942] |
| libnfs | Fix integer overflow [CVE-2026-53689] |
| libraw | Fix out of bounds read issue [CVE-2026-5342]; fix integer overflow issues [CVE-2026-20884 CVE-2026-24450]; fix buffer overflow issues [CVE-2026-20889 CVE-2026-21413 CVE-2026-24660] |
| libsdl2-image | Fix out of bounds read issue [CVE-2026-35444]; improve parser robustness |
| libsdl3-image | Fix out of bounds read issue [CVE-2026-35444]; improve parser robustness |
| libsocket-perl | Fix out of bounds read issue [CVE-2026-12087] |
| libssh2 | Fix buffer overflow issues [CVE-2026-58050 CVE-2026-66035 CVE-2026-58051]; fix double free issue [CVE-2026-66032]; fix integer underflow issue [CVE-2026-66033]; fix data leak issue [CVE-2026-66034] |
| libvirt | Fix buffer overflow issue [CVE-2026-18917]; fix record injection issue [CVE-2026-61477]; fix denial of service issue [CVE-2026-61478]; fix privilege escalation issue [CVE-2026-63622]; fix information disclosure issue [CVE-2026-63623] |
| libwebsockets | Fix denial of service issue [CVE-2026-10650]; fix out of bounds write issue [CVE-2026-78161] |
| llvm-toolchain-22 | New package to support chromium builds |
| lua-geoip | Fix failure to build after geoip downgrade |
| lwip | Fix SNMPv3 authentication buffer overflow [CVE-2026-8836] |
| lxc | Fix memory leak issue; fix running nested containers using current versions of runc |
| mbedtls | Fix signature algorithm injection issue [CVE-2026-25834]; fix PSA random generator cloning issue [CVE-2026-25835]; fix improper validation issue [CVE-2026-34872]; fix client impersonation issue [CVE-2026-34873]; fix NULL pointer dereference issue [CVE-2026-34874]; fix buffer overflow issue [CVE-2026-34875]; fix validation bypass issue [CVE-2026-34876] |
| milib | Handle uncaught exceptions |
| mongo-c-driver | Fix missing input validation issue [CVE-2026-81524] |
| mrtg | Fix privilege escalation issue [CVE-2026-72694] |
| node-lodash | Fix prototype pollution issues [CVE-2025-13465 CVE-2025-13465]; validate imports keys in _.template [CVE-2026-4800] |
| onionshare | Prevent writing files in Receive mode when file uploads are disabled [CVE-2026-54707]; Prevent empty folder from being created when no file is uploaded [CVE-2026-54706] |
| opencryptoki | Fix privilege escalation issue [CVE-2026-23893]; fix out of bounds read issue [CVE-2026-40253] |
| openssl | New upstream release |
| openvpn-dco-dkms | Fix use-after-free in peer teardown |
| org-roam | Add missing dependency on elpa-emacsql-sqlite |
| patool | Fix path traversal vulnerability [CVE-2026-29509] |
| pcre2 | Fix several out of bounds access issues |
| perl | Fix credential forwarding on redirects issue [CVE-2026-7017]; fix symlink extraction issue [CVE-2026-42496]; fix hardlink extraction issue [CVE-2026-42497]; fix out of bounds read issues [CVE-2026-12087 CVE-2026-57432]; fix incorrect regular expression match issue [CVE-2026-13221]; fix header parsing issue [CVE-2025-15649]; fix CRLF validation issue [CVE-2026-7010]; fix buffer overflow issue [CVE-2026-8376]; fix denial of service issue [CVE-2026-48959]; fix crash in zipdetails [CVE-2026-48961]; fix code execution issue [CVE-2026-48962]; fix signed integer overflow issue [CVE-2026-57433] |
| php-guzzlehttp-psr7 | Fix CRLF injection in HTTP start-line parsing [CVE-2026-55766] |
| proftpd-dfsg | Fix SQL injection issue [CVE-2026-44331]; fix buffer overflow issues [CVE-2026-53994 CVE-2026-63090]; fix integer overflow issue [CVE-2026-63091] |
| pyasn1 | Fix denial of service issues [CVE-2026-59884 CVE-2026-59885 CVE-2026-59886] |
| python-ecdsa | Prevent exceptions when handling truncated DER [CVE-2026-33936] |
| python3.13 | Fix use-after-free in dict.clear() with embedded values, resolving regression from previous version; fix injection issue [CVE-2026-0864]; fix file overwrite issue [CVE-2026-11940]; fix denial of service issues [CVE-2026-11972 CVE-2026-6879]; fix incorrect handling of user / group IDs in tar files [CVE-2026-4360] |
| qemu | New upstream stable release; fix integer overflow issue [CVE-2026-15264]; fix secure boot bypass [CVE-2026-16288]; fix infinite loop [CVE-2026-16457]; fix buffer overflow issues [CVE-2026-17516 CVE-2026-50626 CVE-2026-58581 CVE-2026-58582 CVE-2026-63110; virtio-gpu: reject requests with short/truncated control headers [CVE-2026-18054]; fix use-after-free issues [CVE-2026-50624 CVE-2026-63322 CVE-2026-63323]; fix out of bounds write issue [CVE-2026-61402]; hw/uefi: add post_load checks [CVE-2026-61404]; fix denial of service issues [CVE-2026-61405 CVE-2026-61406]; fix memory leak issue [CVE-2026-61476]; fix out of bounds read issues [CVE-2026-63109 CVE-2026-63320 CVE-2026-65928 CVE-2026-65929 CVE-2026-66021]; fix 9pfs Readonly O_TRUNC/O_APPEND Bypass issue [CVE-2026-63318]; virtio: use masked features with set_features_ex [CVE-2026-63321]; virtio-net: qemu_bh_new_guarded uses wrong DeviceState, bypassing MMIO reentrancy protection [CVE-2026-66022] |
| refpolicy | Enable usbguard SELinux policy and fix its confinement; fix SELinux policy for PAM login records, chromium clipboard, pulseaudio, systemd-nspawn/passwd-agent, dhcpc/ntp, and sympa file labelling |
| rsyslog | Fix denial of service issue [CVE-2026-19654]; omfwd regression fix: avoid false active target change log message; fix buffer overflow issues [CVE-2026-78002 CVE-2026-61548] |
| rust-cbindgen-web | New package to support browser builds |
| rustc | Fix documentation merging and fix build on 32-bit ARM platforms; fix tar header processing and an unpack vulnerability [CVE-2026-33055 CVE-2026-33056]; fix cargo credential leakage and cache poisoning [CVE-2026-5222 CVE-2026-5223] |
| rustc-web | New package to support browser builds |
| samba | New upstream stable release |
| sash | Rebuild with updated glibc |
| sbsigntool | Fix intermediate certificate verification |
| sg3-utils | Fix missing sg_inq output fields |
| snapd | Rebuild with updated glibc |
| socat | Fix buffer overflow issue [CVE-2026-56123] |
| spip | Security fixes |
| sqlite3 | Fix FTS5 handling of corrupt records [CVE-2026-11822 CVE-2026-11824] |
| squid | Fix out of bounds read issue [CVE-2026-33515] |
| tini | Rebuild with updated glibc |
| transmission | Fix clickjacking issue [CVE-2026-38978] |
| tripwire | Rebuild with updated glibc |
| tsocks | Rebuild with updated glibc |
| tzdata | New upstream stable release; update timezone data for Alberta and Morocco; update leap second data |
| u-boot | Fix BOOTP/DHCP buffer overread [CVE-2024-42040]; fix FIT signature verification bypass [CVE-2026-46728] |
| unixodbc | Fix memory leaks on dlclose() |
| user-mode-linux | Rebuild with updated linux |
| wolfssl | Fix digest, MAC, and AES-GCM validation [CVE-2026-5194 CVE-2026-6329 CVE-2026-6331 CVE-2026-55967]; fix PKCS7 bounds, overflow, and certificate handling [CVE-2026-6094 CVE-2026-6678 CVE-2026-6681 CVE-2026-7511]; ensure certificate validation [CVE-2026-55960 CVE-2026-55961 CVE-2026-6450 CVE-2026-6731]; fix TLS handshake state and algorithms [CVE-2026-55962 CVE-2026-6092 CVE-2026-6325] |
| xapian-core | Fix missing escaping |
| xfsprogs | Avoid unnecessary permission deniedlogging in other services |
| zsh | Rebuild with updated glibc |
Security Updates
This revision adds the following security updates to the stable release. The Security Team has already released an advisory for each of these updates:
Debian Installer
The installer has been updated to include the fixes incorporated into stable by the point release.
URLs
The complete lists of packages that have changed with this revision:
The current stable distribution:
Proposed updates to the stable distribution:
stable distribution information (release notes, errata etc.):
Security announcements and information:
About Debian
The Debian Project is an association of Free Software developers who volunteer their time and effort in order to produce the completely free operating system Debian.
Contact Information
For further information, please visit the Debian web pages at https://www.debian.org/, send mail to <press@debian.org>, or contact the stable release team at <debian-release@lists.debian.org>.
