Updated Debian 13: 13.4 released

"[email protected]" <[email protected]> Sat, 14 Mar 2026 14:20:27 +0100
Newsgroups gmane.linux.debian.user.announce
Message-ID <[email protected]>
--=-pLLhtGcDUYEAWAaBAMAz
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

------------------------------------------------------------------------
The Debian Project                               https://www.debian.org/
Updated Debian 13: 13.4 released                        [email protected]
March 14th, 2026               https://www.debian.org/News/2026/20260314
------------------------------------------------------------------------


The Debian project is pleased to announce the fourth update of its
stable distribution Debian 13 (codename "trixie"). This point release
mainly adds corrections for security issues, along with a few
adjustments for serious problems. Security advisories have already been
published separately and are referenced where available.

Please note that the point release does not constitute a new version of
Debian 13 but only updates some of the packages included. There is no
need to throw away old "trixie" media. After installation, packages can
be upgraded to the current versions using an up-to-date Debian mirror.

Those who frequently install updates from security.debian.org won't have
to update many packages, and most such updates are included in the point
release.

New installation images will be available soon at the regular locations.

Upgrading an existing installation to this revision can be achieved by
pointing the package management system at one of Debian's many HTTP
mirrors. A comprehensive list of mirrors is available at:

https://www.debian.org/mirror/list



Miscellaneous Bugfixes
----------------------

This stable update adds a few important corrections to the following
packages:

+--------------------------+------------------------------------------+
| Package                  | Reason                                   |
+--------------------------+------------------------------------------+
| akonadi=C2=A0[1]              | Show all folders in kmail                =
|
|                          |                                          |
| apache2=C2=A0[2]              | Fix HTTP/2 regression                    =
|
|                          |                                          |
| arduino-core-avr=C2=A0[3]     | New upstream stable release; fix buffer  =
|
|                          | overflow issue [CVE-2025-69209]          |
|                          |                                          |
| asahi-scripts=C2=A0[4]        | Fix SD card reader autosuspend           =
|
|                          |                                          |
| augeas=C2=A0[5]               | Fix null pointer dereference issue       =
|
|                          | [CVE-2025-2588]                          |
|                          |                                          |
| base-files=C2=A0[6]           | Update for the point release             =
|
|                          |                                          |
| bash=C2=A0[7]                 | Rebuild with updated glibc               =
|
|                          |                                          |
| bglibs=C2=A0[8]               | Rebuild with updated glibc               =
|
|                          |                                          |
| bird2=C2=A0[9]                | Use Restart=3Don-abnormal instead of on- =
  |
|                          | abort; RAdv: Fix flags for deprecated    |
|                          | prefixes; BMP: Fix crash when exporting  |
|                          | a route with non-bgp attributes; ASPA    |
|                          | check fix for AS_SET                     |
|                          |                                          |
| brltty=C2=A0[10]              | Fix taking the VT number from the chosen =
|
|                          | session                                  |
|                          |                                          |
| busybox=C2=A0[11]             | Rebuild with updated glibc               =
|
|                          |                                          |
| capstone=C2=A0[12]            | New upstream stable release; fix buffer  =
|
|                          | overflow issue [CVE-2025-67873]; fix     |
|                          | buffer underflow and overflow issue      |
|                          | [CVE-2025-68114]                         |
|                          |                                          |
| catatonit=C2=A0[13]           | Rebuild with updated glibc               =
|
|                          |                                          |
| cdebootstrap=C2=A0[14]        | Rebuild with updated glibc               =
|
|                          |                                          |
| chkrootkit=C2=A0[15]          | Rebuild with updated glibc               =
|
|                          |                                          |
| chrony=C2=A0[16]              | Open refclock writeable to maintain      =
|
|                          | compatibility with newer kernels         |
|                          |                                          |
| civetweb=C2=A0[17]            | Fix denial of service issue [CVE-2025-   =
|
|                          | 9648]; fix buffer overflow issue         |
|                          | [CVE-2025-55763]                         |
|                          |                                          |
| ckb-next=C2=A0[18]            | Fix init script installation and         =
|
|                          | initialisation; ensure cryptographic     |
|                          | verification of firmware updates         |
|                          |                                          |
| clatd=C2=A0[19]               | Fix systemd unit installation; correct   =
|
|                          | NetworkManager dispatcher install path;  |
|                          | provide example configuration; ensure    |
|                          | obsolete dispatcher script is removed on |
|                          | upgrade                                  |
|                          |                                          |
| condor=C2=A0[20]              | Rebuild with updated glibc               =
|
|                          |                                          |
| dar=C2=A0[21]                 | Rebuild with updated glibc and openssl   =
|
|                          |                                          |
| debian-installer=C2=A0[22]    | Increase Linux kernel ABI to             =
|
|                          | 6.12.73+deb13; rebuild against proposed  |
|                          | updates                                  |
|                          |                                          |
| debian-installer-        | Rebuild against proposed-updates         |
| netboot-images=C2=A0[23]      |                                          =
|
|                          |                                          |
| debian-ports-archive-    | Add  "Debian Ports Archive Automatic     |
| keyring=C2=A0[24]             | Signing Key (2027)" ; move 2025 signing  =
|
|                          | key to the removed keys keyring          |
|                          |                                          |
| debsig-verify=C2=A0[25]       | Rebuild with updated dpkg                =
|
|                          |                                          |
| debvm=C2=A0[26]               | Only use the console in nographics mode; =
|
|                          | use correct variable name; autologin:    |
|                          | prefer credentials to monkey patching    |
|                          | unit; customize-resolved.sh: explicitly  |
|                          | install systemd-resolved                 |
|                          |                                          |
| deets=C2=A0[27]               | Rebuild with updated dpkg                =
|
|                          |                                          |
| direwolf=C2=A0[28]            | Fix stack buffer overflow [CVE-2025-     =
|
|                          | 34457]                                   |
|                          |                                          |
| distribution-gpg-        | Update included keys                     |
| keys=C2=A0[29]                |                                          =
|
|                          |                                          |
| distrobuilder=C2=A0[30]       | Rebuild with updated incus               =
|
|                          |                                          |
| docker.io=C2=A0[31]           | Rebuild with updated glibc               =
|
|                          |                                          |
| dovecot=C2=A0[32]             | Fix possible crash in ldap userdb; fix   =
|
|                          | crash in trash plugin; fix segfault when |
|                          | group ACLs are present but the user has  |
|                          | no groups                                |
|                          |                                          |
| dpkg=C2=A0[33]                | dpkg-query: Fix segfault with empty -S   =
|
|                          | argument; Dpkg::OpenPGP: Do not run      |
|                          | verify with no keyrings;                 |
|                          | Dpkg::Shlibs::Objdump::Object: Add       |
|                          | support for  "Version References"        |
|                          | symbols; Dpkg::OpenPGP::Backend::GnuPG:  |
|                          | Add missing Dpkg::Gettext import; fix    |
|                          | denial of service issue [CVE-2026-2219]  |
|                          |                                          |
| e2fsprogs=C2=A0[34]           | Rebuild with updated glibc               =
|
|                          |                                          |
| ejabberd=C2=A0[35]            | Remove old apparmor profile file         =
|
|                          |                                          |
| ejabberd-contrib=C2=A0[36]    | Rebuild with updated ejabberd            =
|
|                          |                                          |
| erlang=C2=A0[37]              | Fix excessive resource use issues        =
|
|                          | [CVE-2025-48038 CVE-2025-48039 CVE-2025- |
|                          | 48040 CVE-2025-48041]; fix traffic       |
|                          | redirection issue [CVE-2016-1000107]     |
|                          |                                          |
| ffmpegfs=C2=A0[38]            | Fix incomplete listing of files in       =
|
|                          | output directory                         |
|                          |                                          |
| flatpak=C2=A0[39]             | New upstream stable release              =
|
|                          |                                          |
| fluidsynth=C2=A0[40]          | Fix null pointer dereference issue       =
|
|                          | [CVE-2025-56225]                         |
|                          |                                          |
| fonttools=C2=A0[41]           | Fix arbitrary file write issue           =
|
|                          | [CVE-2025-66034]                         |
|                          |                                          |
| glibc=C2=A0[42]               | Update from upstream stable branch; fix  =
|
|                          | heap corruption issue [CVE-2026-0861];   |
|                          | fix stack contents leak issue [CVE-2026- |
|                          | 0915]; fix uninitialized memory use      |
|                          | issue [CVE-2025-15281]; switch currency  |
|                          | symbol for the bg_BG locale to euro; fix |
|                          | a null pointer dereference in symbol     |
|                          | lookup when the symbol version hash is   |
|                          | zero; fix various optimized functions    |
|                          |                                          |
| gnome-shell=C2=A0[43]         | Revert inadvertently backported change   =
|
|                          | that can cause the Shell UI to not       |
|                          | appear on some systems                   |
|                          |                                          |
| gnu-efi=C2=A0[44]             | Fix build of UEFI binaries for armhf     =
|
|                          |                                          |
| gnuais=C2=A0[45]              | Fix displaying the map in gnuaisgui      =
|
|                          |                                          |
| gnupg2=C2=A0[46]              | Rebuild with updated glibc               =
|
|                          |                                          |
| gpsd=C2=A0[47]                | Fix out-of-bounds write issue [CVE-2025- =
|
|                          | 67268]; fix denial of service issue      |
|                          | [CVE-2025-67269]                         |
|                          |                                          |
| grub-efi-amd64-          | Fix ZFS root identification              |
| signed=C2=A0[48]              |                                          =
|
|                          |                                          |
| grub-efi-arm64-          | Fix ZFS root identification              |
| signed=C2=A0[49]              |                                          =
|
|                          |                                          |
| grub-efi-ia32-           | Fix ZFS root identification              |
| signed=C2=A0[50]              |                                          =
|
|                          |                                          |
| grub2=C2=A0[51]               | Fix ZFS root identification              =
|
|                          |                                          |
| ifupdown=C2=A0[52]            | Fix IPv6 DAD handling in ifup; correct   =
|
|                          | dhclient invocation ordering for IPv6;   |
|                          | restore correct executable path          |
|                          | detection in ifup scripts                |
|                          |                                          |
| integrit=C2=A0[53]            | Rebuild with updated glibc               =
|
|                          |                                          |
| jaraco.context=C2=A0[54]      | Prevent path traversal [CVE-2026-23949]  =
|
|                          |                                          |
| libcap2=C2=A0[55]             | Rebuild with updated glibc               =
|
|                          |                                          |
| libguestfs=C2=A0[56]          | Add dependency on isc-dhcp-client        =
|
|                          |                                          |
| libpng1.6=C2=A0[57]           | Fix heap buffer overflow issues          =
|
|                          | [CVE-2026-22801 CVE-2026-22695]          |
|                          |                                          |
| libsndfile=C2=A0[58]          | Fix memory leak issue [CVE-2025-56226]   =
|
|                          |                                          |
| linux-base=C2=A0[59]          | Use compatible hook dir names for        =
|
|                          | headers packages                         |
|                          |                                          |
| lxc=C2=A0[60]                 | Fix data corruption during heavy IO on   =
|
|                          | PTS; update lxc-default-with-nesting     |
|                          | apparmor profile; rebuild with updated   |
|                          | glibc                                    |
|                          |                                          |
| mariadb=C2=A0[61]             | New upstream stable release; fix         =
|
|                          | arbitrary code execution issue           |
|                          | [CVE-2025-13699]; fix denial of service  |
|                          | issue [CVE-CVE-2026-21968]; use          |
|                          | tmpfiles.d to generate runtime           |
|                          | directory; fix upgrades from version     |
|                          | 10.4 when encryption is enabled; fix     |
|                          | innodb_linux_aio support                 |
|                          |                                          |
| mpg123=C2=A0[62]              | Do not modify raw ID3v2 data while       =
|
|                          | parsing                                  |
|                          |                                          |
| node-proxy-agents=C2=A0[63]   | Fix path traversal issue [CVE-2026-      =
|
|                          | 27699]                                   |
|                          |                                          |
| open-iscsi=C2=A0[64]          | Fix discovery of  "static"  nodes        =
|
|                          |                                          |
| openssh=C2=A0[65]             | Fix mistracking of MaxStartups process   =
|
|                          | exits in some situations; fix possible   |
|                          | code execution issues [CVE-2025-61984    |
|                          | CVE-2025-61985]                          |
|                          |                                          |
| openssl=C2=A0[66]             | New upstream stable release              =
|
|                          |                                          |
| passt=C2=A0[67]               | Increase AppArmor ABI version to 4.0 to  =
|
|                          | enable user namespace creation           |
|                          |                                          |
| pcsx2=C2=A0[68]               | Fix code execution issue [CVE-2025-      =
|
|                          | 49589]                                   |
|                          |                                          |
| pdudaemon=C2=A0[69]           | Add missing dependency on setuputils     =
|
|                          |                                          |
| phpunit=C2=A0[70]             | Fix unsafe deserialization issue         =
|
|                          | [CVE-2026-24765]                         |
|                          |                                          |
| plastimatch=C2=A0[71]         | Repack to exclude non-free source files  =
|
|                          |                                          |
| policyd-rate-limit=C2=A0[72]  | Fix operation with Python >=3D 3.12      =
  |
|                          |                                          |
| postgresql-17=C2=A0[73]       | New upstream stable release; fix buffer  =
|
|                          | overrun issue [CVE-2026-2006]            |
|                          |                                          |
| python-cryptography=C2=A0[74] | Fix missing validation in EC public key  =
|
|                          | creation [CVE-2026-26007]                |
|                          |                                          |
| python-filelock=C2=A0[75]     | Fix TOCTOU symlink handling              =
|
|                          | vulnerability in lock file creation      |
|                          | [CVE-2025-68146]                         |
|                          |                                          |
| python-multipart=C2=A0[76]    | Fix arbitrary file write issue           =
|
|                          | [CVE-2026-24486]                         |
|                          |                                          |
| python-os-ken=C2=A0[77]       | Accept empty  "OXM"  fields              =
|
|                          |                                          |
| python-pyspnego=C2=A0[78]     | Fix deprecation warnings                 =
|
|                          |                                          |
| qemu=C2=A0[79]                | New upstream stable release; fix denial  =
|
|                          | of service issues [CVE-2025-14876        |
|                          | CVE-2026-0665]                           |
|                          |                                          |
| qtbase-opensource-       | Fix data races; X11: set fallback        |
| src=C2=A0[80]                 | logical DPI to 96, fixing incorrect      =
|
|                          | calculation                              |
|                          |                                          |
| reprepro=C2=A0[81]            | Fix incorrect tracking data when copying =
|
|                          | packages                                 |
|                          |                                          |
| requests=C2=A0[82]            | Fix credential leak issue [CVE-2024-     =
|
|                          | 47081]                                   |
|                          |                                          |
| riseup-vpn=C2=A0[83]          | Support additional polkit providers      =
|
|                          |                                          |
| runit-services=C2=A0[84]      | Slim: start in foreground with -n; dbus- =
|
|                          | dep.fixer: correctly test for existing   |
|                          | services definitions, only start dbus    |
|                          | services, even with the sysv override    |
|                          |                                          |
| rust-ntp-proto=C2=A0[85]      | Fix excessive load issue [CVE-2026-      =
|
|                          | 26076]                                   |
|                          |                                          |
| rust-ntpd=C2=A0[86]           | Rebuild with rust-ntp-proto 1.4.0-       =
|
|                          | 4+deb13u1 to fix CVE-2026-26076          |
|                          |                                          |
| rust-tealdeer=C2=A0[87]       | Update archive URL                       =
|
|                          |                                          |
| samba=C2=A0[88]               | New upstream stable release              =
|
|                          |                                          |
| sash=C2=A0[89]                | Rebuild with updated glibc               =
|
|                          |                                          |
| scilab=C2=A0[90]              | Fix build failure                        =
|
|                          |                                          |
| snapd=C2=A0[91]               | Rebuild with updated glibc               =
|
|                          |                                          |
| sqlite3=C2=A0[92]             | Prevent integer overflow in FTSS         =
|
|                          | extension [CVE-2025-7709]; add missing   |
|                          | build dependency on pkgconf              |
|                          |                                          |
| starlette=C2=A0[93]           | Fix denial of service issue [CVE-2025-   =
|
|                          | 62727]                                   |
|                          |                                          |
| sudo=C2=A0[94]                | Only enable Intel CET on amd64; fix      =
|
|                          | regression with sudoers.d filenames      |
|                          | containing colons                        |
|                          |                                          |
| suricata=C2=A0[95]            | Fix denial of service issues [CVE-2026-  =
|
|                          | 22258 CVE-2026-22259 CVE-2026-22261];    |
|                          | fix stack overflow issue [CVE-2026-      |
|                          | 22262]; fix heap overflow issue          |
|                          | [CVE-2026-22264]                         |
|                          |                                          |
| tayga=C2=A0[96]               | Fix EAM mapping for host addresses       =
|
|                          |                                          |
| tini=C2=A0[97]                | Rebuild with updated glibc               =
|
|                          |                                          |
| torsocks=C2=A0[98]            | Use correct environment variable;        =
|
|                          | explicitly trigger ldconfig trigger      |
|                          |                                          |
| tripwire=C2=A0[99]            | Rebuild with updated glibc               =
|
|                          |                                          |
| tsocks=C2=A0[100]             | Rebuild with updated glibc               =
|
|                          |                                          |
| tzdata=C2=A0[101]             | New upstream release; Moldova has used   =
|
|                          | EU transition times since 2022           |
|                          |                                          |
| uglifyjs=C2=A0[102]           | Fix test failure                         =
|
|                          |                                          |
| units=C2=A0[103]              | Update URLs to packetizer.com            =
|
|                          |                                          |
| user-mode-linux=C2=A0[104]    | Rebuild with updated linux               =
|
|                          |                                          |
| wget2=C2=A0[105]              | Fix file overwrite issue with metalink   =
|
|                          | [CVE-2025-69194]; fix remote buffer      |
|                          | overflow [CVE-2025-69195]                |
|                          |                                          |
| wireless-regdb=C2=A0[106]     | New upstream stable release; update      =
|
|                          | regulatory information for several       |
|                          | countries                                |
|                          |                                          |
| wireshark=C2=A0[107]          | New upstream stable release; fix USB HID =
|
|                          | dissector memory exhaustion [CVE-2026-   |
|                          | 3201]; fix RF4CE Profile dissector crash |
|                          | [CVE-2026-3203]                          |
|                          |                                          |
| xen=C2=A0[108]                | New upstream stable release; fix buffer  =
|
|                          | overrun issue [CVE-2025-58150]; fix      |
|                          | incomplete vCPU isolation issue          |
|                          | [CVE-2026-23553]                         |
|                          |                                          |
| zabbix=C2=A0[109]             | New upstream stable release; fix data    =
|
|                          | leakage issues [CVE-2025-27231 CVE-2025- |
|                          | 27233 CVE-2025-27236 CVE-2025-27238      |
|                          | CVE-2025-49641]; fix denial of service   |
|                          | issue [CVE-2025-49643]                   |
|                          |                                          |
| zookeeper=C2=A0[110]          | Fix build failure by skipping some flaky =
|
|                          | tests                                    |
|                          |                                          |
| zsh=C2=A0[111]                | Rebuild with updated glibc               =
|
|                          |                                          |
+--------------------------+------------------------------------------+

    1: https://packages.debian.org/src:akonadi
    2: https://packages.debian.org/src:apache2
    3: https://packages.debian.org/src:arduino-core-avr
    4: https://packages.debian.org/src:asahi-scripts
    5: https://packages.debian.org/src:augeas
    6: https://packages.debian.org/src:base-files
    7: https://packages.debian.org/src:bash
    8: https://packages.debian.org/src:bglibs
    9: https://packages.debian.org/src:bird2
   10: https://packages.debian.org/src:brltty
   11: https://packages.debian.org/src:busybox
   12: https://packages.debian.org/src:capstone
   13: https://packages.debian.org/src:catatonit
   14: https://packages.debian.org/src:cdebootstrap
   15: https://packages.debian.org/src:chkrootkit
   16: https://packages.debian.org/src:chrony
   17: https://packages.debian.org/src:civetweb
   18: https://packages.debian.org/src:ckb-next
   19: https://packages.debian.org/src:clatd
   20: https://packages.debian.org/src:condor
   21: https://packages.debian.org/src:dar
   22: https://packages.debian.org/src:debian-installer
   23: https://packages.debian.org/src:debian-installer-netboot-images
   24: https://packages.debian.org/src:debian-ports-archive-keyring
   25: https://packages.debian.org/src:debsig-verify
   26: https://packages.debian.org/src:debvm
   27: https://packages.debian.org/src:deets
   28: https://packages.debian.org/src:direwolf
   29: https://packages.debian.org/src:distribution-gpg-keys
   30: https://packages.debian.org/src:distrobuilder
   31: https://packages.debian.org/src:docker.io
   32: https://packages.debian.org/src:dovecot
   33: https://packages.debian.org/src:dpkg
   34: https://packages.debian.org/src:e2fsprogs
   35: https://packages.debian.org/src:ejabberd
   36: https://packages.debian.org/src:ejabberd-contrib
   37: https://packages.debian.org/src:erlang
   38: https://packages.debian.org/src:ffmpegfs
   39: https://packages.debian.org/src:flatpak
   40: https://packages.debian.org/src:fluidsynth
   41: https://packages.debian.org/src:fonttools
   42: https://packages.debian.org/src:glibc
   43: https://packages.debian.org/src:gnome-shell
   44: https://packages.debian.org/src:gnu-efi
   45: https://packages.debian.org/src:gnuais
   46: https://packages.debian.org/src:gnupg2
   47: https://packages.debian.org/src:gpsd
   48: https://packages.debian.org/src:grub-efi-amd64-signed
   49: https://packages.debian.org/src:grub-efi-arm64-signed
   50: https://packages.debian.org/src:grub-efi-ia32-signed
   51: https://packages.debian.org/src:grub2
   52: https://packages.debian.org/src:ifupdown
   53: https://packages.debian.org/src:integrit
   54: https://packages.debian.org/src:jaraco.context
   55: https://packages.debian.org/src:libcap2
   56: https://packages.debian.org/src:libguestfs
   57: https://packages.debian.org/src:libpng1.6
   58: https://packages.debian.org/src:libsndfile
   59: https://packages.debian.org/src:linux-base
   60: https://packages.debian.org/src:lxc
   61: https://packages.debian.org/src:mariadb
   62: https://packages.debian.org/src:mpg123
   63: https://packages.debian.org/src:node-proxy-agents
   64: https://packages.debian.org/src:open-iscsi
   65: https://packages.debian.org/src:openssh
   66: https://packages.debian.org/src:openssl
   67: https://packages.debian.org/src:passt
   68: https://packages.debian.org/src:pcsx2
   69: https://packages.debian.org/src:pdudaemon
   70: https://packages.debian.org/src:phpunit
   71: https://packages.debian.org/src:plastimatch
   72: https://packages.debian.org/src:policyd-rate-limit
   73: https://packages.debian.org/src:postgresql-17
   74: https://packages.debian.org/src:python-cryptography
   75: https://packages.debian.org/src:python-filelock
   76: https://packages.debian.org/src:python-multipart
   77: https://packages.debian.org/src:python-os-ken
   78: https://packages.debian.org/src:python-pyspnego
   79: https://packages.debian.org/src:qemu
   80: https://packages.debian.org/src:qtbase-opensource-src
   81: https://packages.debian.org/src:reprepro
   82: https://packages.debian.org/src:requests
   83: https://packages.debian.org/src:riseup-vpn
   84: https://packages.debian.org/src:runit-services
   85: https://packages.debian.org/src:rust-ntp-proto
   86: https://packages.debian.org/src:rust-ntpd
   87: https://packages.debian.org/src:rust-tealdeer
   88: https://packages.debian.org/src:samba
   89: https://packages.debian.org/src:sash
   90: https://packages.debian.org/src:scilab
   91: https://packages.debian.org/src:snapd
   92: https://packages.debian.org/src:sqlite3
   93: https://packages.debian.org/src:starlette
   94: https://packages.debian.org/src:sudo
   95: https://packages.debian.org/src:suricata
   96: https://packages.debian.org/src:tayga
   97: https://packages.debian.org/src:tini
   98: https://packages.debian.org/src:torsocks
   99: https://packages.debian.org/src:tripwire
  100: https://packages.debian.org/src:tsocks
  101: https://packages.debian.org/src:tzdata
  102: https://packages.debian.org/src:uglifyjs
  103: https://packages.debian.org/src:units
  104: https://packages.debian.org/src:user-mode-linux
  105: https://packages.debian.org/src:wget2
  106: https://packages.debian.org/src:wireless-regdb
  107: https://packages.debian.org/src:wireshark
  108: https://packages.debian.org/src:xen
  109: https://packages.debian.org/src:zabbix
  110: https://packages.debian.org/src:zookeeper
  111: https://packages.debian.org/src:zsh

Security Updates
----------------

This revision adds the following security updates to the stable release.
The Security Team has already released an advisory for each of these
updates:

+----------------+---------------------------------+
| Advisory ID    | Package                         |
+----------------+---------------------------------+
| DSA-6054=C2=A0[112] | firefox-esr=C2=A0[113]               |
|                |                                 |
| DSA-6078=C2=A0[114] | firefox-esr=C2=A0[115]               |
|                |                                 |
| DSA-6093=C2=A0[116] | gimp=C2=A0[117]                      |
|                |                                 |
| DSA-6094=C2=A0[118] | libsodium=C2=A0[119]                 |
|                |                                 |
| DSA-6095=C2=A0[120] | foomuuri=C2=A0[121]                  |
|                |                                 |
| DSA-6096=C2=A0[122] | vlc=C2=A0[123]                       |
|                |                                 |
| DSA-6097=C2=A0[124] | chromium=C2=A0[125]                  |
|                |                                 |
| DSA-6098=C2=A0[126] | net-snmp=C2=A0[127]                  |
|                |                                 |
| DSA-6099=C2=A0[128] | python-parsl=C2=A0[129]              |
|                |                                 |
| DSA-6100=C2=A0[130] | chromium=C2=A0[131]                  |
|                |                                 |
| DSA-6101=C2=A0[132] | firefox-esr=C2=A0[133]               |
|                |                                 |
| DSA-6102=C2=A0[134] | python-urllib3=C2=A0[135]            |
|                |                                 |
| DSA-6103=C2=A0[136] | thunderbird=C2=A0[137]               |
|                |                                 |
| DSA-6104=C2=A0[138] | python-keystonemiddleware=C2=A0[139] |
|                |                                 |
| DSA-6105=C2=A0[140] | modsecurity-crs=C2=A0[141]           |
|                |                                 |
| DSA-6106=C2=A0[142] | inetutils=C2=A0[143]                 |
|                |                                 |
| DSA-6107=C2=A0[144] | bind9=C2=A0[145]                     |
|                |                                 |
| DSA-6108=C2=A0[146] | chromium=C2=A0[147]                  |
|                |                                 |
| DSA-6109=C2=A0[148] | incus=C2=A0[149]                     |
|                |                                 |
| DSA-6111=C2=A0[150] | imagemagick=C2=A0[151]               |
|                |                                 |
| DSA-6112=C2=A0[152] | openjdk-21=C2=A0[153]                |
|                |                                 |
| DSA-6113=C2=A0[154] | openssl=C2=A0[155]                   |
|                |                                 |
| DSA-6114=C2=A0[156] | pyasn1=C2=A0[157]                    |
|                |                                 |
| DSA-6115=C2=A0[158] | gimp=C2=A0[159]                      |
|                |                                 |
| DSA-6116=C2=A0[160] | chromium=C2=A0[161]                  |
|                |                                 |
| DSA-6117=C2=A0[162] | python-django=C2=A0[163]             |
|                |                                 |
| DSA-6118=C2=A0[164] | thunderbird=C2=A0[165]               |
|                |                                 |
| DSA-6119=C2=A0[166] | jtreg8=C2=A0[167]                    |
|                |                                 |
| DSA-6119=C2=A0[168] | openjdk-25=C2=A0[169]                |
|                |                                 |
| DSA-6120=C2=A0[170] | tomcat10=C2=A0[171]                  |
|                |                                 |
| DSA-6121=C2=A0[172] | tomcat11=C2=A0[173]                  |
|                |                                 |
| DSA-6122=C2=A0[174] | chromium=C2=A0[175]                  |
|                |                                 |
| DSA-6123=C2=A0[176] | xrdp=C2=A0[177]                      |
|                |                                 |
| DSA-6124=C2=A0[178] | wireshark=C2=A0[179]                 |
|                |                                 |
| DSA-6125=C2=A0[180] | usbmuxd=C2=A0[181]                   |
|                |                                 |
| DSA-6126=C2=A0[182] | linux-signed-amd64=C2=A0[183]        |
|                |                                 |
| DSA-6126=C2=A0[184] | linux-signed-arm64=C2=A0[185]        |
|                |                                 |
| DSA-6126=C2=A0[186] | linux=C2=A0[187]                     |
|                |                                 |
| DSA-6128=C2=A0[188] | shaarli=C2=A0[189]                   |
|                |                                 |
| DSA-6129=C2=A0[190] | munge=C2=A0[191]                     |
|                |                                 |
| DSA-6130=C2=A0[192] | haproxy=C2=A0[193]                   |
|                |                                 |
| DSA-6131=C2=A0[194] | nginx=C2=A0[195]                     |
|                |                                 |
| DSA-6133=C2=A0[196] | postgresql-17=C2=A0[197]             |
|                |                                 |
| DSA-6134=C2=A0[198] | pdns-recursor=C2=A0[199]             |
|                |                                 |
| DSA-6135=C2=A0[200] | chromium=C2=A0[201]                  |
|                |                                 |
| DSA-6137=C2=A0[202] | roundcube=C2=A0[203]                 |
|                |                                 |
| DSA-6138=C2=A0[204] | libpng1.6=C2=A0[205]                 |
|                |                                 |
| DSA-6139=C2=A0[206] | gimp=C2=A0[207]                      |
|                |                                 |
| DSA-6140=C2=A0[208] | gnutls28=C2=A0[209]                  |
|                |                                 |
| DSA-6141=C2=A0[210] | linux-signed-amd64=C2=A0[211]        |
|                |                                 |
| DSA-6141=C2=A0[212] | linux-signed-arm64=C2=A0[213]        |
|                |                                 |
| DSA-6141=C2=A0[214] | linux=C2=A0[215]                     |
|                |                                 |
| DSA-6142=C2=A0[216] | gegl=C2=A0[217]                      |
|                |                                 |
| DSA-6143=C2=A0[218] | libvpx=C2=A0[219]                    |
|                |                                 |
| DSA-6144=C2=A0[220] | inetutils=C2=A0[221]                 |
|                |                                 |
| DSA-6145=C2=A0[222] | nova=C2=A0[223]                      |
|                |                                 |
| DSA-6146=C2=A0[224] | chromium=C2=A0[225]                  |
|                |                                 |
| DSA-6147=C2=A0[226] | pillow=C2=A0[227]                    |
|                |                                 |
| DSA-6148=C2=A0[228] | firefox-esr=C2=A0[229]               |
|                |                                 |
| DSA-6149=C2=A0[230] | nss=C2=A0[231]                       |
|                |                                 |
| DSA-6150=C2=A0[232] | python-django=C2=A0[233]             |
|                |                                 |
| DSA-6151=C2=A0[234] | chromium=C2=A0[235]                  |
|                |                                 |
| DSA-6152=C2=A0[236] | thunderbird=C2=A0[237]               |
|                |                                 |
| DSA-6153=C2=A0[238] | lxd=C2=A0[239]                       |
|                |                                 |
| DSA-6155=C2=A0[240] | spip=C2=A0[241]                      |
|                |                                 |
| DSA-6156=C2=A0[242] | gimp=C2=A0[243]                      |
|                |                                 |
| DSA-6157=C2=A0[244] | chromium=C2=A0[245]                  |
|                |                                 |
+----------------+---------------------------------+

  112: https://www.debian.org/security/2025/dsa-6054
  113: https://packages.debian.org/src:firefox-esr
  114: https://www.debian.org/security/2025/dsa-6078
  115: https://packages.debian.org/src:firefox-esr
  116: https://www.debian.org/security/2026/dsa-6093
  117: https://packages.debian.org/src:gimp
  118: https://www.debian.org/security/2026/dsa-6094
  119: https://packages.debian.org/src:libsodium
  120: https://www.debian.org/security/2026/dsa-6095
  121: https://packages.debian.org/src:foomuuri
  122: https://www.debian.org/security/2026/dsa-6096
  123: https://packages.debian.org/src:vlc
  124: https://www.debian.org/security/2026/dsa-6097
  125: https://packages.debian.org/src:chromium
  126: https://www.debian.org/security/2026/dsa-6098
  127: https://packages.debian.org/src:net-snmp
  128: https://www.debian.org/security/2026/dsa-6099
  129: https://packages.debian.org/src:python-parsl
  130: https://www.debian.org/security/2026/dsa-6100
  131: https://packages.debian.org/src:chromium
  132: https://www.debian.org/security/2026/dsa-6101
  133: https://packages.debian.org/src:firefox-esr
  134: https://www.debian.org/security/2026/dsa-6102
  135: https://packages.debian.org/src:python-urllib3
  136: https://www.debian.org/security/2026/dsa-6103
  137: https://packages.debian.org/src:thunderbird
  138: https://www.debian.org/security/2026/dsa-6104
  139: https://packages.debian.org/src:python-keystonemiddleware
  140: https://www.debian.org/security/2026/dsa-6105
  141: https://packages.debian.org/src:modsecurity-crs
  142: https://www.debian.org/security/2026/dsa-6106
  143: https://packages.debian.org/src:inetutils
  144: https://www.debian.org/security/2026/dsa-6107
  145: https://packages.debian.org/src:bind9
  146: https://www.debian.org/security/2026/dsa-6108
  147: https://packages.debian.org/src:chromium
  148: https://www.debian.org/security/2026/dsa-6109
  149: https://packages.debian.org/src:incus
  150: https://www.debian.org/security/2026/dsa-6111
  151: https://packages.debian.org/src:imagemagick
  152: https://www.debian.org/security/2026/dsa-6112
  153: https://packages.debian.org/src:openjdk-21
  154: https://www.debian.org/security/2026/dsa-6113
  155: https://packages.debian.org/src:openssl
  156: https://www.debian.org/security/2026/dsa-6114
  157: https://packages.debian.org/src:pyasn1
  158: https://www.debian.org/security/2026/dsa-6115
  159: https://packages.debian.org/src:gimp
  160: https://www.debian.org/security/2026/dsa-6116
  161: https://packages.debian.org/src:chromium
  162: https://www.debian.org/security/2026/dsa-6117
  163: https://packages.debian.org/src:python-django
  164: https://www.debian.org/security/2026/dsa-6118
  165: https://packages.debian.org/src:thunderbird
  166: https://www.debian.org/security/2026/dsa-6119
  167: https://packages.debian.org/src:jtreg8
  168: https://www.debian.org/security/2026/dsa-6119
  169: https://packages.debian.org/src:openjdk-25
  170: https://www.debian.org/security/2026/dsa-6120
  171: https://packages.debian.org/src:tomcat10
  172: https://www.debian.org/security/2026/dsa-6121
  173: https://packages.debian.org/src:tomcat11
  174: https://www.debian.org/security/2026/dsa-6122
  175: https://packages.debian.org/src:chromium
  176: https://www.debian.org/security/2026/dsa-6123
  177: https://packages.debian.org/src:xrdp
  178: https://www.debian.org/security/2026/dsa-6124
  179: https://packages.debian.org/src:wireshark
  180: https://www.debian.org/security/2026/dsa-6125
  181: https://packages.debian.org/src:usbmuxd
  182: https://www.debian.org/security/2026/dsa-6126
  183: https://packages.debian.org/src:linux-signed-amd64
  184: https://www.debian.org/security/2026/dsa-6126
  185: https://packages.debian.org/src:linux-signed-arm64
  186: https://www.debian.org/security/2026/dsa-6126
  187: https://packages.debian.org/src:linux
  188: https://www.debian.org/security/2026/dsa-6128
  189: https://packages.debian.org/src:shaarli
  190: https://www.debian.org/security/2026/dsa-6129
  191: https://packages.debian.org/src:munge
  192: https://www.debian.org/security/2026/dsa-6130
  193: https://packages.debian.org/src:haproxy
  194: https://www.debian.org/security/2026/dsa-6131
  195: https://packages.debian.org/src:nginx
  196: https://www.debian.org/security/2026/dsa-6133
  197: https://packages.debian.org/src:postgresql-17
  198: https://www.debian.org/security/2026/dsa-6134
  199: https://packages.debian.org/src:pdns-recursor
  200: https://www.debian.org/security/2026/dsa-6135
  201: https://packages.debian.org/src:chromium
  202: https://www.debian.org/security/2026/dsa-6137
  203: https://packages.debian.org/src:roundcube
  204: https://www.debian.org/security/2026/dsa-6138
  205: https://packages.debian.org/src:libpng1.6
  206: https://www.debian.org/security/2026/dsa-6139
  207: https://packages.debian.org/src:gimp
  208: https://www.debian.org/security/2026/dsa-6140
  209: https://packages.debian.org/src:gnutls28
  210: https://www.debian.org/security/2026/dsa-6141
  211: https://packages.debian.org/src:linux-signed-amd64
  212: https://www.debian.org/security/2026/dsa-6141
  213: https://packages.debian.org/src:linux-signed-arm64
  214: https://www.debian.org/security/2026/dsa-6141
  215: https://packages.debian.org/src:linux
  216: https://www.debian.org/security/2026/dsa-6142
  217: https://packages.debian.org/src:gegl
  218: https://www.debian.org/security/2026/dsa-6143
  219: https://packages.debian.org/src:libvpx
  220: https://www.debian.org/security/2026/dsa-6144
  221: https://packages.debian.org/src:inetutils
  222: https://www.debian.org/security/2026/dsa-6145
  223: https://packages.debian.org/src:nova
  224: https://www.debian.org/security/2026/dsa-6146
  225: https://packages.debian.org/src:chromium
  226: https://www.debian.org/security/2026/dsa-6147
  227: https://packages.debian.org/src:pillow
  228: https://www.debian.org/security/2026/dsa-6148
  229: https://packages.debian.org/src:firefox-esr
  230: https://www.debian.org/security/2026/dsa-6149
  231: https://packages.debian.org/src:nss
  232: https://www.debian.org/security/2026/dsa-6150
  233: https://packages.debian.org/src:python-django
  234: https://www.debian.org/security/2026/dsa-6151
  235: https://packages.debian.org/src:chromium
  236: https://www.debian.org/security/2026/dsa-6152
  237: https://packages.debian.org/src:thunderbird
  238: https://www.debian.org/security/2026/dsa-6153
  239: https://packages.debian.org/src:lxd
  240: https://www.debian.org/security/2026/dsa-6155
  241: https://packages.debian.org/src:spip
  242: https://www.debian.org/security/2026/dsa-6156
  243: https://packages.debian.org/src:gimp
  244: https://www.debian.org/security/2026/dsa-6157
  245: https://packages.debian.org/src:chromium

Debian Installer
----------------

The installer has been updated to include the fixes incorporated into
stable by the point release.


URLs
----

The complete lists of packages that have changed with this revision:

https://deb.debian.org/debian/dists/trixie/ChangeLog


The current stable distribution:

https://deb.debian.org/debian/dists/stable/


Proposed updates to the stable distribution:

https://deb.debian.org/debian/dists/proposed-updates


stable distribution information (release notes, errata etc.):

https://www.debian.org/releases/stable/


Security announcements and information:

https://www.debian.org/security/



About Debian
------------

The Debian Project is an association of Free Software developers who
volunteer their time and effort in order to produce the completely free
operating system Debian.


Contact Information
-------------------

For further information, please visit the Debian web pages at
https://www.debian.org/, send mail to <[email protected]>, or contact the
stable release team at <[email protected]>.

--=-pLLhtGcDUYEAWAaBAMAz
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part

-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEEcH/R3vmpi4JWBoDfeBP2a44wMXIFAmm1YJsACgkQeBP2a44w
MXJhCw//W2Tzd+1iJvg/wdWrdj9dx/byvnUOjoBfkNg9EWOHibx7G8nbWl8frZlq
zQJPfIzGKgQND+wFHR5uipdmmfrj5z1WmyijTole7IBsURufUTw6ZXSqWh+VUmIa
EYcPxZ/xivKIlSJKiWUOmybeBHGO7H9E0OQvHVTzVDHNJtaBZP/+zYzWvxmzsanB
BFrDCeghKbw1RmSCOji158eZRsincsf2DVWPjSqPnCI/IcYXdBbdsq35WZKo8Xlu
EzUztGUDihj0MyqoIPHKxn/f0L+fMO/16DuMHZYBSzr59mud7XgTEBJFIxK8s+YC
McDjpQ682zdXDRkv0brkNthkwPLzTudSLujOnccbSe7cEiYcQNgykBnYAT7ASaZw
fGzFJIepx4qZiZyIa++quWHlYe57Td8sloY/C524+4QIHYfILhQVrvPoN5XNSYJ7
cYCsmCWOVDdYLjFhtoYGg8rQSZqV+VrMSatwC5n8hg1h16XeY0ED3KwG/+uFLH6e
9IkJTzJL5d7RiVKJPySRnoQ75F+35oDT0w52PiaKJOBiXVMXmjm3y5zwb0TTSFBJ
MBba9ohTbHUFozF8Hi1vqEfcbr1zxNrf5g3GgTtNdktE4mW9msc76uq+VbA+GO6G
FWz5NtORVhqxbKspHfzVne0Wg/oawwVoBQYTNS57QgaM2KnZmA4=
=yO7z
-----END PGP SIGNATURE-----

--=-pLLhtGcDUYEAWAaBAMAz--