Updated Debian 13: 13.7 released

September 12th, 2026

The Debian project is pleased to announce the seventh update of its stable distribution Debian 13 (codename trixie). This point release mainly adds corrections for security issues, along with a few adjustments for serious problems. Security advisories have already been published separately and are referenced where available.

Please note that the point release does not constitute a new version of Debian 13 but only updates some of the packages included. There is no need to throw away old trixie media. After installation, packages can be upgraded to the current versions using an up-to-date Debian mirror.

Those who frequently install updates from security.debian.org won't have to update many packages, and most such updates are included in the point release.

New installation images will be available soon at the regular locations.

Upgrading an existing installation to this revision can be achieved by pointing the package management system at one of Debian's many HTTP mirrors. A comprehensive list of mirrors is available at:

https://www.debian.org/mirror/list

Miscellaneous Bugfixes

This stable update adds a few important corrections to the following packages:

Package Reason
akonadi-search Fix crash with empty input
alsa-lib Fix heap overflow issue [CVE-2026-25068]
ansible-core New upstream stable release; fix arbitrary code injection issue [CVE-2026-11332]
at-spi2-core Fix atkversion.h header for C++ linkage
audit Add support for the riscv64 architecture
auto-apt-proxy Prevent apt-helper call from recursing into auto-apt-proxy; wait for network to be online
awffull Fix visit / page statistics
base-files Update for the point release; add AGPL-3.0, Artistic-2.0, BSL-1.0, CC-BY-3.0, CC-BY-4.0, CC-BY-SA-3.0, CC-BY-SA-4.0, GFDL-1.1 and OFL-1.1 to common-licenses
bash Rebuild with updated glibc
bcg729 Fix division by zero
bettercap Fix mysql.server module remote DoS via crafted client handshake [CVE-2026-8276]; stop installing systemd service by default
bglibs Rebuild with updated glibc
binwalk Fix path traversal issue [CVE-2026-7179]
busybox Rebuild with updated glibc
catatonit Rebuild with updated glibc
cdebootstrap Rebuild with updated glibc
chkrootkit Rebuild with updated glibc
cinnamon Fix download and update of spices (applets, desklets, extensions and themes)
condor Rebuild with updated glibc
curl Fix OpenSSL engine loading return value; remove trailing whitespaces causing test failures
cyrus-imapd Allow JMAP EventSource without WebSocket/wslay; fix insufficient access check issues [CVE-2026-47084 CVE-2026-47086 CVE-2026-47087 CVE-2026-47081 CVE-2026-47089 CVE-2026-47085 CVE-2026-47083 CVE-2026-47082]; fix out of bounds read issue [CVE-2026-47088]
dar Rebuild with updated glibc; rebuild with updated curl; fix glibc Built-Using regression
dcmtk Fix denial of service issues [CVE-2026-35505 CVE-2026-44628 CVE-2026-50254]; fix path traversal issues [CVE-2026-50003 CVE-2026-52868]
debian-edu-config New upstream stable release
debian-edu-install Skip Icinga 2 IDO MySQL dbconfig setup
debian-installer Bump linux ABI to 6.12.107+deb13; rebuild for the point release
debian-installer-netboot-images Rebuild against proposed-updates
dhcpcd Fix IPv6 Neighbor Discovery option parsing to discard advertisements with zero-length options [CVE-2026-14258]
dnsmasq Fix buffer overflow issue [CVE-2026-12725]; fix out of bounds read issue [CVE-2026-12969]
docker.io Rebuild with updated glibc
flask Ensure Vary: Cookie is set on session access [CVE-2026-27205]
fluidsynth Fix buffer overflow issues [CVE-2026-58264 CVE-2026-61714]
glib2.0 Fix out of bounds access issues [CVE-2026-58010 CVE-2026-58011 CVE-2026-58012 CVE-2026-58013 CVE-2026-58014]; fix file content disclosure issue [CVE-2026-58015]; fix denial of service issue [CVE-2026-15588]; fix integer underflow issue [CVE-2026-58016]; fix out of bounds write issue [CVE-2026-16118]
glibc Fix buffer overflow/underflow issues [CVE-2026-5928 CVE-2026-5450]; ensure compatibility with linux 7.0 headers
gnupg2 Rebuild with updated glibc
goaccess Fix out of bounds write issue [CVE-2026-54715]; fix denial of service issue [CVE-2026-55768 CVE-2026-55777]
gpsd Fix gpsprof command and code injection in gnuplot script generation [CVE-2026-58459 CVE-2026-60122]
gzip Fix insecure temporary file handling issue [CVE-2026-41991]; fix buffer overflow issue [CVE-2026-41992]
imagemagick Fix buffer overflow issues [CVE-2026-56362 CVE-2026-56372 CVE-2026-56374 CVE-2026-61464]; fix memory leak issues [CVE-2026-56366 CVE-2026-56375 CVE-2026-61863 CVE-2026-61864 CVE-2026-61865 CVE-2026-61866 CVE-2026-61867 CVE-2026-61868 CVE-2026-61869 CVE-2026-61870 CVE-2026-61871 CVE-2026-61872]; fix use-after-free issues [CVE-2026-56373 CVE-2026-61857 CVE-2026-61860 CVE-2026-61861]; fix denial of service issue [CVE-2026-61465]; fix policy bypass issues [CVE-2026-61858 CVE-2026-61859]; fix information disclosure issue [CVE-2026-61862]
incus Fix path traversal issue [CVE-2026-81500]; fix insufficent access check issue [CVE-2026-81501]
integrit Rebuild with updated glibc
libcap2 Rebuild with updated glibc
libdatetime-timezone-perl Update to Olson 2026c; Alberta, CA permanently -06; Morocco, permanently 00
libdbd-csv-perl Fix test failure
libhttp-tiny-perl Fix CRLF validation issue [CVE-2026-7010]; fix credential forwarding on redirects issue [CVE-2026-7017]
libio-compress-perl Fix header parsing issue [CVE-2025-15649]; fix denial of service issue [CVE-2026-48959]; fix crash in zipdetails [CVE-2026-48961]; fix code execution issue [CVE-2026-48962]
libmodule-cpants-analyse-perl Fix interoperability with Archive::Tar >= 3.08
libmongocrypt Fix missing input validation issue [CVE-2026-81523]
libnet-cidr-set-perl Fix IPv4/IPv6 CIDR parsing validation [CVE-2026-49940 CVE-2026-49941 CVE-2026-49942]
libnfs Fix integer overflow [CVE-2026-53689]
libraw Fix out of bounds read issue [CVE-2026-5342]; fix integer overflow issues [CVE-2026-20884 CVE-2026-24450]; fix buffer overflow issues [CVE-2026-20889 CVE-2026-21413 CVE-2026-24660]
libsdl2-image Fix out of bounds read issue [CVE-2026-35444]; improve parser robustness
libsdl3-image Fix out of bounds read issue [CVE-2026-35444]; improve parser robustness
libsocket-perl Fix out of bounds read issue [CVE-2026-12087]
libssh2 Fix buffer overflow issues [CVE-2026-58050 CVE-2026-66035 CVE-2026-58051]; fix double free issue [CVE-2026-66032]; fix integer underflow issue [CVE-2026-66033]; fix data leak issue [CVE-2026-66034]
libvirt Fix buffer overflow issue [CVE-2026-18917]; fix record injection issue [CVE-2026-61477]; fix denial of service issue [CVE-2026-61478]; fix privilege escalation issue [CVE-2026-63622]; fix information disclosure issue [CVE-2026-63623]
libwebsockets Fix denial of service issue [CVE-2026-10650]; fix out of bounds write issue [CVE-2026-78161]
llvm-toolchain-22 New package to support chromium builds
lua-geoip Fix failure to build after geoip downgrade
lwip Fix SNMPv3 authentication buffer overflow [CVE-2026-8836]
lxc Fix memory leak issue; fix running nested containers using current versions of runc
mbedtls Fix signature algorithm injection issue [CVE-2026-25834]; fix PSA random generator cloning issue [CVE-2026-25835]; fix improper validation issue [CVE-2026-34872]; fix client impersonation issue [CVE-2026-34873]; fix NULL pointer dereference issue [CVE-2026-34874]; fix buffer overflow issue [CVE-2026-34875]; fix validation bypass issue [CVE-2026-34876]
milib Handle uncaught exceptions
mongo-c-driver Fix missing input validation issue [CVE-2026-81524]
mrtg Fix privilege escalation issue [CVE-2026-72694]
node-lodash Fix prototype pollution issues [CVE-2025-13465 CVE-2025-13465]; validate imports keys in _.template [CVE-2026-4800]
onionshare Prevent writing files in Receive mode when file uploads are disabled [CVE-2026-54707]; Prevent empty folder from being created when no file is uploaded [CVE-2026-54706]
opencryptoki Fix privilege escalation issue [CVE-2026-23893]; fix out of bounds read issue [CVE-2026-40253]
openssl New upstream release
openvpn-dco-dkms Fix use-after-free in peer teardown
org-roam Add missing dependency on elpa-emacsql-sqlite
patool Fix path traversal vulnerability [CVE-2026-29509]
pcre2 Fix several out of bounds access issues
perl Fix credential forwarding on redirects issue [CVE-2026-7017]; fix symlink extraction issue [CVE-2026-42496]; fix hardlink extraction issue [CVE-2026-42497]; fix out of bounds read issues [CVE-2026-12087 CVE-2026-57432]; fix incorrect regular expression match issue [CVE-2026-13221]; fix header parsing issue [CVE-2025-15649]; fix CRLF validation issue [CVE-2026-7010]; fix buffer overflow issue [CVE-2026-8376]; fix denial of service issue [CVE-2026-48959]; fix crash in zipdetails [CVE-2026-48961]; fix code execution issue [CVE-2026-48962]; fix signed integer overflow issue [CVE-2026-57433]
php-guzzlehttp-psr7 Fix CRLF injection in HTTP start-line parsing [CVE-2026-55766]
proftpd-dfsg Fix SQL injection issue [CVE-2026-44331]; fix buffer overflow issues [CVE-2026-53994 CVE-2026-63090]; fix integer overflow issue [CVE-2026-63091]
pyasn1 Fix denial of service issues [CVE-2026-59884 CVE-2026-59885 CVE-2026-59886]
python-ecdsa Prevent exceptions when handling truncated DER [CVE-2026-33936]
python3.13 Fix use-after-free in dict.clear() with embedded values, resolving regression from previous version; fix injection issue [CVE-2026-0864]; fix file overwrite issue [CVE-2026-11940]; fix denial of service issues [CVE-2026-11972 CVE-2026-6879]; fix incorrect handling of user / group IDs in tar files [CVE-2026-4360]
qemu New upstream stable release; fix integer overflow issue [CVE-2026-15264]; fix secure boot bypass [CVE-2026-16288]; fix infinite loop [CVE-2026-16457]; fix buffer overflow issues [CVE-2026-17516 CVE-2026-50626 CVE-2026-58581 CVE-2026-58582 CVE-2026-63110; virtio-gpu: reject requests with short/truncated control headers [CVE-2026-18054]; fix use-after-free issues [CVE-2026-50624 CVE-2026-63322 CVE-2026-63323]; fix out of bounds write issue [CVE-2026-61402]; hw/uefi: add post_load checks [CVE-2026-61404]; fix denial of service issues [CVE-2026-61405 CVE-2026-61406]; fix memory leak issue [CVE-2026-61476]; fix out of bounds read issues [CVE-2026-63109 CVE-2026-63320 CVE-2026-65928 CVE-2026-65929 CVE-2026-66021]; fix 9pfs Readonly O_TRUNC/O_APPEND Bypass issue [CVE-2026-63318]; virtio: use masked features with set_features_ex [CVE-2026-63321]; virtio-net: qemu_bh_new_guarded uses wrong DeviceState, bypassing MMIO reentrancy protection [CVE-2026-66022]
refpolicy Enable usbguard SELinux policy and fix its confinement; fix SELinux policy for PAM login records, chromium clipboard, pulseaudio, systemd-nspawn/passwd-agent, dhcpc/ntp, and sympa file labelling
rsyslog Fix denial of service issue [CVE-2026-19654]; omfwd regression fix: avoid false active target change log message; fix buffer overflow issues [CVE-2026-78002 CVE-2026-61548]
rust-cbindgen-web New package to support browser builds
rustc Fix documentation merging and fix build on 32-bit ARM platforms; fix tar header processing and an unpack vulnerability [CVE-2026-33055 CVE-2026-33056]; fix cargo credential leakage and cache poisoning [CVE-2026-5222 CVE-2026-5223]
rustc-web New package to support browser builds
samba New upstream stable release
sash Rebuild with updated glibc
sbsigntool Fix intermediate certificate verification
sg3-utils Fix missing sg_inq output fields
snapd Rebuild with updated glibc
socat Fix buffer overflow issue [CVE-2026-56123]
spip Security fixes
sqlite3 Fix FTS5 handling of corrupt records [CVE-2026-11822 CVE-2026-11824]
squid Fix out of bounds read issue [CVE-2026-33515]
tini Rebuild with updated glibc
transmission Fix clickjacking issue [CVE-2026-38978]
tripwire Rebuild with updated glibc
tsocks Rebuild with updated glibc
tzdata New upstream stable release; update timezone data for Alberta and Morocco; update leap second data
u-boot Fix BOOTP/DHCP buffer overread [CVE-2024-42040]; fix FIT signature verification bypass [CVE-2026-46728]
unixodbc Fix memory leaks on dlclose()
user-mode-linux Rebuild with updated linux
wolfssl Fix digest, MAC, and AES-GCM validation [CVE-2026-5194 CVE-2026-6329 CVE-2026-6331 CVE-2026-55967]; fix PKCS7 bounds, overflow, and certificate handling [CVE-2026-6094 CVE-2026-6678 CVE-2026-6681 CVE-2026-7511]; ensure certificate validation [CVE-2026-55960 CVE-2026-55961 CVE-2026-6450 CVE-2026-6731]; fix TLS handshake state and algorithms [CVE-2026-55962 CVE-2026-6092 CVE-2026-6325]
xapian-core Fix missing escaping
xfsprogs Avoid unnecessary permission denied logging in other services
zsh Rebuild with updated glibc

Security Updates

This revision adds the following security updates to the stable release. The Security Team has already released an advisory for each of these updates:

Advisory ID Package
DSA-6381 linux-signed-amd64
DSA-6381 linux-signed-arm64
DSA-6381 linux
DSA-6382 postfix
DSA-6383 imagemagick
DSA-6385 pgextwlist
DSA-6386 opam
DSA-6387 chromium
DSA-6388 libxfont
DSA-6389 ntfs-3g
DSA-6390 chromium
DSA-6391 roundcube
DSA-6392 tiff
DSA-6393 linux-signed-amd64
DSA-6393 linux-signed-arm64
DSA-6393 linux
DSA-6394 firefox-esr
DSA-6395 bind9
DSA-6396 chromium
DSA-6397 pdns-recursor
DSA-6398 webkit2gtk
DSA-6399 wordpress
DSA-6400 exim4
DSA-6401 samba
DSA-6402 hplip
DSA-6403 nss
DSA-6404 expat
DSA-6405 linux-signed-amd64
DSA-6405 linux-signed-arm64
DSA-6405 linux
DSA-6406 php8.4
DSA-6407 incus
DSA-6409 libgd2
DSA-6410 libssh
DSA-6411 aom
DSA-6413 libde265
DSA-6414 udisks2
DSA-6415 linux-signed-amd64
DSA-6415 linux-signed-arm64
DSA-6415 linux
DSA-6416 jq
DSA-6417 libheif
DSA-6419 dnsdist
DSA-6420 pdns
DSA-6421 pdns-recursor
DSA-6423 kitty
DSA-6424 xen
DSA-6425 openjdk-21
DSA-6427 wordpress
DSA-6428 libyaml-syck-perl
DSA-6429 caddy
DSA-6430 postfix
DSA-6432 flatpak
DSA-6433 xdg-dbus-proxy
DSA-6434 lemonldap-ng
DSA-6435 spip
DSA-6437 apr-util
DSA-6438 postgresql-17
DSA-6439 zip
DSA-6440 unzip
DSA-6441 python-httplib2
DSA-6442 util-linux
DSA-6443 docker.io
DSA-6444 neutron
DSA-6445 ironic
DSA-6446 expat
DSA-6447 librabbitmq
DSA-6448 spip
DSA-6449 swift
DSA-6450 srt
DSA-6451 firefox-esr
DSA-6452 designate
DSA-6453 libgit2
DSA-6454 sabnzbdplus
DSA-6456 spip
DSA-6457 openjdk-21
DSA-6458 gst-plugins-bad1.0
DSA-6459 libnet-dns-perl
DSA-6460 openjdk-25
DSA-6462 zfs-linux
DSA-6463 webkit2gtk
DSA-6464 erlang
DSA-6465 openssl
DSA-6466 linux-signed-amd64
DSA-6466 linux-signed-arm64
DSA-6466 linux
DSA-6467 freecad
DSA-6468 emacs
DSA-6469 xrdp
DSA-6470 gimp
DSA-6471 wireshark
DSA-6472 bubblewrap
DSA-6473 libdbi-perl
DSA-6474 cockpit
DSA-6475 suricata-update
DSA-6477 linux-signed-amd64
DSA-6477 linux-signed-arm64
DSA-6477 linux
DSA-6478 starlette
DSA-6479 roundcube
DSA-6480 keystone
DSA-6481 firefox-esr
DSA-6485 tryton-modules-company
DSA-6485 tryton-modules-marketing-automation
DSA-6485 tryton-modules-marketing-email
DSA-6485 tryton-server
DSA-6486 libde265

Debian Installer

The installer has been updated to include the fixes incorporated into stable by the point release.

URLs

The complete lists of packages that have changed with this revision:

https://deb.debian.org/debian/dists/trixie/ChangeLog

The current stable distribution:

https://deb.debian.org/debian/dists/stable/

Proposed updates to the stable distribution:

https://deb.debian.org/debian/dists/proposed-updates

stable distribution information (release notes, errata etc.):

https://www.debian.org/releases/stable/

Security announcements and information:

https://www.debian.org/security/

About Debian

The Debian Project is an association of Free Software developers who volunteer their time and effort in order to produce the completely free operating system Debian.

Contact Information

For further information, please visit the Debian web pages at https://www.debian.org/, send mail to <press@debian.org>, or contact the stable release team at <debian-release@lists.debian.org>.