Updated Debian 13: 13.6 released

"[email protected]" <[email protected]> Sat, 11 Jul 2026 14:10:11 +0200
Newsgroups gmane.linux.debian.user.announce
Message-ID <[email protected]>
--=-Je7Wie/A9xqEGmXLpcs1
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

------------------------------------------------------------------------
The Debian Project                               https://www.debian.org/
Updated Debian 13: 13.6 released                        [email protected]
July 11th, 2026                https://www.debian.org/News/2026/20260711
------------------------------------------------------------------------


The Debian project is pleased to announce the sixth update of its stable
distribution Debian 13 (codename "trixie"). This point release mainly
adds corrections for security issues, along with a few adjustments for
serious problems. Security advisories have already been published
separately and are referenced where available.

Please note that the point release does not constitute a new version of
Debian 13 but only updates some of the packages included. There is no
need to throw away old "trixie" media. After installation, packages can
be upgraded to the current versions using an up-to-date Debian mirror.

Those who frequently install updates from security.debian.org won't have
to update many packages, and most such updates are included in the point
release.

New installation images will be available soon at the regular locations.

Upgrading an existing installation to this revision can be achieved by
pointing the package management system at one of Debian's many HTTP
mirrors. A comprehensive list of mirrors is available at:

https://www.debian.org/mirror/list



Noteworthy updates
------------------

"fwupd" has been updated to upstream version 2.0.20, which has the
ability to update the Secure Boot certificate authority (CA), Key
Exchange Key (KEK) and revocation (DBX) databases.

The 2013 UEFI Secure Boot CA installed by default on most PCs and used
to sign bootloaders has now expired. Future updates to "shim-signed"
could therefore lead to systems being unable to boot with Secure Boot
enabled.

Users are strongly advised to apply "CA", "KEK" and "DBX" updates from
their system OEM in line with the following guidance:

https://wiki.debian.org/SecureBoot/CAChanges#What_should_I_do.3F


For licensing reasons "geoip-database" has been reverted to a version
dated approximately December 2019. As a result, applications using this
database might use out-of-date allocation information.

More recent versions of "geoip-database" (GeoLite) are not compatible
with the Debian Free Software Guidelines and cannot be distributed.

Consumers of this data are strongly encouraged to obtain a GeoLite
license directly and cease reliance on the "geoip-database" package.


Miscellaneous Bugfixes
----------------------

This stable update adds a few important corrections to the following
packages:

+-------------------------+-------------------------------------------+
| Package                 | Reason                                    |
+-------------------------+-------------------------------------------+
| apache2=C2=A0[1]             | Fix use-after-free issues [CVE-2026-29167 =
|
|                         | CVE-2026-48913]; fix cross-site scripting |
|                         | issue [CVE-2026-29170]; fix buffer        |
|                         | overflow issues [CVE-2026-34355 CVE-2026- |
|                         | 34356 CVE-2026-42536]; fix denial of      |
|                         | service issues [CVE-2026-42535 CVE-2026-  |
|                         | 44186 CVE-2026-49975]; fix out of bounds  |
|                         | read issues [CVE-2026-43951 CVE-2026-     |
|                         | 44185]; fix file read issue [CVE-2026-    |
|                         | 44119]; fix buffer underwrite issue       |
|                         | [CVE-2026-44631]                          |
|                         |                                           |
| archlinux-keyring=C2=A0[2]   | Update keys                               =
|
|                         |                                           |
| awstats=C2=A0[3]             | Prevent freezing on keyword stat          =
|
|                         |                                           |
| base-files=C2=A0[4]          | Update for the point release              =
|
|                         |                                           |
| beets=C2=A0[5]               | Fix XSS vulnerability [CVE-2026-42052]    =
|
|                         |                                           |
| calibre=C2=A0[6]             | Fix unsafe e-book extraction and resource =
|
|                         | path handling [CVE-2026-30853 CVE-2026-   |
|                         | 33206]; prevent e-book viewer local file  |
|                         | reads and SSRF/exfiltration [CVE-2026-    |
|                         | 33205]; avoid unsafe catalog rule         |
|                         | evaluation; correct XPath and SQL query   |
|                         | handling; fix reader-background endpoint  |
|                         | path normalisation; improve exception     |
|                         | diagnostics                               |
|                         |                                           |
| cdebootstrap=C2=A0[7]        | Rebuild with updated xz-utils             =
|
|                         |                                           |
| chrony=C2=A0[8]              | Ensure if-up/down hook scripts exit       =
|
|                         | successfully                              |
|                         |                                           |
| ckermit=C2=A0[9]             | Block remote control of the local kermit  =
|
|                         | by default [CVE-2025-68920]; disable      |
|                         | unnecessary OpenSSL version check         |
|                         |                                           |
| composer=C2=A0[10]           | Fix support for new GitHub token format   =
|
|                         | [CVE-2026-45793]                          |
|                         |                                           |
| courier=C2=A0[11]            | Fix webadmin paths to imapd and imapd-ssl =
|
|                         |                                           |
| curl=C2=A0[12]               | Fix bearer token redirect leaks           =
|
|                         | [CVE-2025-14524 CVE-2026-3783]; correct   |
|                         | OpenSSL CA cache reuse [CVE-2025-14819];  |
|                         | fix HTTP Negotiate and proxy connection   |
|                         | reuse [CVE-2026-1965 CVE-2026-3784        |
|                         | CVE-2026-5545]; prevent clear-text        |
|                         | STARTTLS connection reuse [CVE-2026-      |
|                         | 4873]; fix SMB use-after-free and wrong   |
|                         | share reuse [CVE-2026-3805 CVE-2026-      |
|                         | 5773]; clear redirected host/proxy/netrc  |
|                         | credentials [CVE-2026-6253 CVE-2026-      |
|                         | 6429]; prevent stale cookie leaks         |
|                         | [CVE-2026-6276]; clear proxy Digest state |
|                         | when switching proxies [CVE-2026-7168]    |
|                         |                                           |
| dar=C2=A0[13]                | Rebuild with updated curl, libgcrypt20,   =
|
|                         | openssl                                   |
|                         |                                           |
| dcmtk=C2=A0[14]              | Fix NULL pointer dereference issues       =
|
|                         | [CVE-2022-4981 CVE-2025-14841]; fix       |
|                         | memory corruption issues [CVE-2025-2357   |
|                         | CVE-2025-9732 CVE-2025-14607]; fix        |
|                         | command injection issue [CVE-2026-5663];  |
|                         | fix buffer overflow issues [CVE-2026-     |
|                         | 10194 CVE-2026-12805]                     |
|                         |                                           |
| debian-installer=C2=A0[15]   | Bump linux ABI 6.12.94+deb13; rebuild for =
|
|                         | point release                             |
|                         |                                           |
| debian-installer-       | Rebuild from proposed updates             |
| netboot-images=C2=A0[16]     |                                           =
|
|                         |                                           |
| debusine=C2=A0[17]           | Enforce file upload permissions; restrict =
|
|                         | artifact relation creation/deletion       |
|                         | [CVE-2026-11852]; harden sbuild           |
|                         | repository command quoting; reject        |
|                         | unsafe .dsc/.changes checksum paths       |
|                         | [CVE-2026-11853]                          |
|                         |                                           |
| deepdiff=C2=A0[18]           | Fix class pollution issue [CVE-2025-      =
|
|                         | 58367]; fix denial of service issue       |
|                         | [CVE-2026-33155]                          |
|                         |                                           |
| dhcpcd=C2=A0[19]             | Fix memory safety issues [CVE-2025-70102  =
|
|                         | CVE-2026-56113 CVE-2026-56114]; fix IPv6  |
|                         | Router Advertisement information leakage  |
|                         | [CVE-2026-56116]; correct control socket  |
|                         | lifetime handling [CVE-2026-56117]        |
|                         |                                           |
| distrobuilder=C2=A0[20]      | Rebuild with updated incus                =
|
|                         |                                           |
| dolphin=C2=A0[21]            | Fix sandbox escape issue [CVE-2026-41525] =
|
|                         |                                           |
| errands=C2=A0[22]            | Fix verification of TLS certificates for  =
|
|                         | CalDAV servers [CVE-2025-71063]           |
|                         |                                           |
| execnet=C2=A0[23]            | Disable unreliable build-time tests       =
|
|                         |                                           |
| fldigi=C2=A0[24]             | Force LC_NUMERIC=3DC.UTF-8 to use proper  =
  |
|                         | decimal separator in API and ADIF log     |
|                         | files                                     |
|                         |                                           |
| freecad=C2=A0[25]            | Fix fanuc post processor; fix build       =
|
|                         | failure on arm64                          |
|                         |                                           |
| fwupd=C2=A0[26]              | Enable UEFI CA/db/KEK updates for the     =
|
|                         | 2026 Secure Boot certificate transition;  |
|                         | fix UEFI PK/KEK/dbx enumeration; fix      |
|                         | Thunderbolt controller deployment;        |
|                         | correct firmware update regressions;      |
|                         | update fwupd hardware support and tests   |
|                         |                                           |
| gambas3=C2=A0[27]            | Fix Qt component loading                  =
|
|                         |                                           |
| gdown=C2=A0[28]              | Fix arbitray file write issue [CVE-2026-  =
|
|                         | 40491]                                    |
|                         |                                           |
| geoip=C2=A0[29]              | Reinstate generator scripts, relied upon  =
|
|                         | by geoip-database                         |
|                         |                                           |
| geoip-database=C2=A0[30]     | Revert to a DFSG-compatible version       =
|
|                         |                                           |
| giflib=C2=A0[31]             | Fix memory corruption issues [CVE-2026-   =
|
|                         | 23868 CVE-2026-26740]                     |
|                         |                                           |
| gimp=C2=A0[32]               | Fix integer overflow issues [CVE-2026-    =
|
|                         | 4154 CVE-2026-40915]                      |
|                         |                                           |
| gnupg2=C2=A0[33]             | Rebuild with updated libgcrypt20          =
|
|                         |                                           |
| gnustep-sqlclient=C2=A0[34]  | Remove Multi-Arch: same                   =
|
|                         |                                           |
| graphite2=C2=A0[35]          | Fix out-of-bounds write [CVE-2026-50593]  =
|
|                         |                                           |
| horizon=C2=A0[36]            | Fix escaping of special characters in     =
|
|                         | project                                   |
|                         |                                           |
| ironic=C2=A0[37]             | Fix credential forwarding from            =
|
|                         | configuration molds [CVE-2026-42997]; fix |
|                         | IPMI console command injection [CVE-2026- |
|                         | 42510]; sandbox kickstart template        |
|                         | rendering [CVE-2026-44916]; prevent       |
|                         | conductor thread exhaustion from file     |
|                         | special devices [CVE-2026-44919];         |
|                         | restrict unsafe file image paths; improve |
|                         | image download validation and             |
|                         | checksumming; correct Redfish power, boot |
|                         | and firmware workflows; fix inspection    |
|                         | rule validation and hook failures; avoid  |
|                         | stuck service/deploy states               |
|                         |                                           |
| isc-kea=C2=A0[38]            | Fix denial of service issue [CVE-2026-    =
|
|                         | 3608]                                     |
|                         |                                           |
| isenkram=C2=A0[39]           | Handle usr-merge migration in update-fw-  =
|
|                         | list; update generated firmware lists     |
|                         |                                           |
| keystone=C2=A0[40]           | Fix behaviour of user_enabled_invert      =
|
|                         | [CVE-2026-40683]; prevent unauthorized    |
|                         | EC2 credential creation and deletion      |
|                         | [CVE-2026-33551]                          |
|                         |                                           |
| libapache-session-      | Improve entropy source [CVE-2026-8503]    |
| browseable-perl=C2=A0[41]    |                                           =
|
|                         |                                           |
| libass=C2=A0[42]             | Fix out of bounds read and write issues   =
|
|                         |                                           |
| libbytes-random-secure- | Fix incorrect usage of seed in PRNG       |
| perl=C2=A0[43]               | [CVE-2026-11625]                          =
|
|                         |                                           |
| libcaca=C2=A0[44]            | Prevent undefined behaviour in overflow   =
|
|                         | check [CVE-2026-42046]                    |
|                         |                                           |
| libcrypt-pbkdf2-        | Change default hash algorithm to HMAC-    |
| perl=C2=A0[45]               | SHA256 and default iterations to 600,000  =
|
|                         | [CVE-2026-9641]; generate salts using     |
|                         | Crypt::URandom [CVE-2026-9638]; use a     |
|                         | constant-time comparison in `validate` to |
|                         | avoid timing attacks [CVE-2017-20240]     |
|                         |                                           |
| libcrypt-urandom-       | Fix buffer overflow issue [CVE-2026-2474] |
| perl=C2=A0[46]               |                                           =
|
|                         |                                           |
| libhtml-parser-         | Fix heap-use-after-free in                |
| perl=C2=A0[47]               | _decode_entities [CVE-2026-8829]          =
|
|                         |                                           |
| libnet-cidr-lite-       | Fix IP/CIDR parser validation: reject     |
| perl=C2=A0[48]               | non-ASCII digits and trailing newlines    =
|
|                         | [CVE-2026-55190]; reject zero-padded CIDR |
|                         | masks [CVE-2026-45191]                    |
|                         |                                           |
| libreoffice=C2=A0[49]        | Gracefully handle failure in graphite2    =
|
|                         |                                           |
| libslirp=C2=A0[50]           | Fix memory disclosure issue [CVE-2026-    =
|
|                         | 9539]                                     |
|                         |                                           |
| libtasn1-6=C2=A0[51]         | Fix buffer overflow issue [CVE-2025-      =
|
|                         | 13151]                                    |
|                         |                                           |
| libvncserver=C2=A0[52]       | Fix buffer overflow and out-of-bounds     =
|
|                         | write [CVE-2026-44988 CVE-2026-50538]     |
|                         |                                           |
| libxml-libxml-perl=C2=A0[53] | Fix out-of-bounds read [CVE-2026-8177]    =
|
|                         |                                           |
| libxml2=C2=A0[54]            | Fix RelaxNG include recursion limits      =
|
|                         | [CVE-2026-0989]; prevent XML and SGML     |
|                         | catalog recursion/resource exhaustion     |
|                         | [CVE-2025-8732 CVE-2026-0990 CVE-2026-    |
|                         | 0992]; fix xmllint shell memory leak      |
|                         | [CVE-2026-1757]; correct XML writer and   |
|                         | Schematron error-path leaks; avoid        |
|                         | RelaxNG validation use-after-free; update |
|                         | regression tests                          |
|                         |                                           |
| libxpm=C2=A0[55]             | Fix out of bounds read issue [CVE-2026-   =
|
|                         | 4367]                                     |
|                         |                                           |
| linuxcnc=C2=A0[56]           | Sanitize module names                     =
|
|                         |                                           |
| lxml-html-clean=C2=A0[57]    | Fix filter bypass issue [CVE-2026-28348]; =
|
|                         | fix tag injection issue [CVE-2026-28350]  |
|                         |                                           |
| mesa=C2=A0[58]               | Fix WebGPU/SPIR-V allocation handling     =
|
|                         | [CVE-2026-40393]                          |
|                         |                                           |
| miniupnpd=C2=A0[59]          | Fix integer underflow issue [CVE-2026-    =
|
|                         | 5720]                                     |
|                         |                                           |
| modsecurity=C2=A0[60]        | Prevent denial of service in hexDecode    =
|
|                         | handling [CVE-2026-30923]; prevent denial |
|                         | of service in SSN/CPF/SVNR verification   |
|                         | [CVE-2026-42268]                          |
|                         |                                           |
| mutt=C2=A0[61]               | Fix buffer truncation issues [CVE-2026-   =
|
|                         | 43859 CVE-2026-43860 CVE-2026-43861]; fix |
|                         | mishandling of imap_auth_gss security     |
|                         | level [CVE-2026-43862]; fix denial of     |
|                         | service issue [CVE-2026-43863]; fix NULL  |
|                         | pointer dereference issue [CVE-2026-      |
|                         | 43864]                                    |
|                         |                                           |
| mxml=C2=A0[62]               | Fix out-of-bounds read [CVE-2026-5037]    =
|
|                         |                                           |
| nbconvert=C2=A0[63]          | Fix arbitrary file read/write issues      =
|
|                         | [CVE-2026-39377 CVE-2026-39378]           |
|                         |                                           |
| neutron=C2=A0[64]            | Fix tagging policy bypass                 =
|
|                         |                                           |
| nss=C2=A0[65]                | Improve handling of escape sequences in   =
|
|                         | pk11uri_ParseAttributes [CVE-2026-12318]  |
|                         |                                           |
| ojalgo=C2=A0[66]             | Reduce frequency of built-time test       =
|
|                         | failures                                  |
|                         |                                           |
| opencc=C2=A0[67]             | Fix out-of-bounds read issue [CVE-2025-   =
|
|                         | 15536]                                    |
|                         |                                           |
| openslide=C2=A0[68]          | Fix possible code execution issue         =
|
|                         | [CVE-2026-48977]                          |
|                         |                                           |
| php-guzzlehttp-         | Fix Host authority validation [CVE-2026-  |
| psr7=C2=A0[69]               | 48998]; reject control characters in URI  =
|
|                         | hosts [CVE-2026-49214]; harden            |
|                         | ServerRequest globals handling; normalise |
|                         | global header values; encode literal plus |
|                         | signs in query helpers                    |
|                         |                                           |
| php-league-csv=C2=A0[70]     | Fix build time test with PHP >=3D8.4.14   =
  |
|                         |                                           |
| php-twig=C2=A0[71]           | Security update                           =
|
|                         |                                           |
| pillow=C2=A0[72]             | Followup fix for CVE-2026-42310           =
|
|                         |                                           |
| poco=C2=A0[73]               | Fix segmentation fault [CVE-2025-6375]    =
|
|                         |                                           |
| poetry=C2=A0[74]             | Fix arbitrary file write issue [CVE-2026- =
|
|                         | 34591]                                    |
|                         |                                           |
| poppler=C2=A0[75]            | Fix invalid signature creation issue      =
|
|                         |                                           |
| postfix=C2=A0[76]            | New upstream stable release; fix denial   =
|
|                         | of service issue [CVE-2026-43964]; keep   |
|                         | daemon running during upgrades            |
|                         |                                           |
| protobuf=C2=A0[77]           | Fix parser recursion limits [CVE-2024-    =
|
|                         | 7254 CVE-2025-4565 CVE-2026-0994          |
|                         | CVE-2026-6409]                            |
|                         |                                           |
| psd-tools=C2=A0[78]          | Fix denial of service issue [CVE-2026-    =
|
|                         | 27809]                                    |
|                         |                                           |
| pupnp=C2=A0[79]              | Fix SSRF port confusion issue [CVE-2026-  =
|
|                         | 41682]                                    |
|                         |                                           |
| pymdown-extensions=C2=A0[80] | Fix regular expression-based denial of    =
|
|                         | service issue [CVE-2025-68142]            |
|                         |                                           |
| pyopenssl=C2=A0[81]          | Fix handling of exceptions and connection =
|
|                         | cancelling [CVE-2026-27448]; fix buffer   |
|                         | overflow in DTLS cookie callback          |
|                         | [CVE-2026-27459]                          |
|                         |                                           |
| pytest-httpbin=C2=A0[82]     | Disable unreliable build-time test        =
|
|                         |                                           |
| python-daphne=C2=A0[83]      | Fix denial of service issue [CVE-2026-    =
|
|                         | 44545]; fix header injection issue        |
|                         | [CVE-2026-44546]                          |
|                         |                                           |
| python-django=C2=A0[84]      | Update test suite following changes in    =
|
|                         | python3.13                                |
|                         |                                           |
| python-dynaconf=C2=A0[85]    | Fix Server-Side Template Injection issue  =
|
|                         | [CVE-2026-33154]                          |
|                         |                                           |
| python-grpc-tools=C2=A0[86]  | Fix TypeError in                          =
|
|                         | command.build_package_protos              |
|                         |                                           |
| python-handy-           | Fix end of central diretory locator for   |
| archives=C2=A0[87]           | Zip64                                     =
|
|                         |                                           |
| python-idna=C2=A0[88]        | Fix denial of service issue [CVE-2026-    =
|
|                         | 45409]                                    |
|                         |                                           |
| python-iniparse=C2=A0[89]    | Fix race condition in build-time tests    =
|
|                         |                                           |
| python-jwcrypto=C2=A0[90]    | Fix denial of service issue [CVE-2026-    =
|
|                         | 39373]                                    |
|                         |                                           |
| python-markdown=C2=A0[91]    | Adapt to changes in Python's html.parser  =
|
|                         | module                                    |
|                         |                                           |
| python-marshmallow=C2=A0[92] | Fix denial of service issue [CVE-2025-    =
|
|                         | 68480]                                    |
|                         |                                           |
| python-memray=C2=A0[93]      | Fix cross-site scripting issue [CVE-2026- =
|
|                         | 32722]                                    |
|                         |                                           |
| python-virtualenv=C2=A0[94]  | Fix time-of-check / time-of-use issues    =
|
|                         | [CVE-2026-22702]                          |
|                         |                                           |
| python-webob=C2=A0[95]       | Fix open redirect issue [CVE-2026-44889]  =
|
|                         |                                           |
| python-xmltodict=C2=A0[96]   | Fix XML injection issue [CVE-2025-9375]   =
|
|                         |                                           |
| python3.13=C2=A0[97]         | Fix a crash in SNI callback when the SSL  =
|
|                         | object is gone; fix reference leaks in    |
|                         | ssl.SSLContext objects; avoid garbage     |
|                         | collecting objects too early when sharing |
|                         | __dict__; fix  "CR/LF bytes were not      |
|                         | rejected by HTTP client proxy tunnel      |
|                         | headers or host"  [CVE-2026-1502]; fix    |
|                         | denial of service issues [CVE-2026-3276   |
|                         | CVE-2026-9669]; fix insufficient escaping |
|                         | issue [CVE-2026-6019]; fix path traversal |
|                         | issue [CVE-2026-7774]; fix server-side    |
|                         | request forgery issue [CVE-2026-8328]     |
|                         |                                           |
| qemu=C2=A0[98]               | New upstream stable release; security     =
|
|                         | fixes [CVE-2024-6519 CVE-2026-2243        |
|                         | CVE-2026-3195 CVE-2026-3196 CVE-2026-3842 |
|                         | CVE-2026-3886 CVE-2026-3890 CVE-2026-     |
|                         | 41435 CVE-2026-41436 CVE-2026-41437       |
|                         | CVE-2026-41438 CVE-2026-41439 CVE-2026-   |
|                         | 41440 CVE-2026-5744 CVE-2026-5761         |
|                         | CVE-2026-5763 CVE-2026-6502 CVE-2026-8341 |
|                         | CVE-2026-48002 CVE-2026-48003 CVE-2026-   |
|                         | 48004 CVE-2026-48914 CVE-2026-48915       |
|                         | CVE-2026-6425 CVE-2026-8343]              |
|                         |                                           |
| qtmir=C2=A0[99]              | Fix Lomiri rendering, scaling, focus      =
|
|                         | handling, and session crash issues;       |
|                         | correct stale window and dead surface     |
|                         | cleanup; ensure Xwayland applications     |
|                         | inherit DISPLAY; improve Asahi Linux      |
|                         | rendering provider selection              |
|                         |                                           |
| rauc=C2=A0[100]              | Fix improper signing of large bundles     =
|
|                         | [CVE-2026-34155]                          |
|                         |                                           |
| resource-agents=C2=A0[101]   | Fix syntax error                          =
|
|                         |                                           |
| rhino=C2=A0[102]             | Fix denial of service issue [CVE-2025-    =
|
|                         | 66453]                                    |
|                         |                                           |
| rlottie=C2=A0[103]           | Fix out-of-bounds read issue [CVE-2026-   =
|
|                         | 10305]; fix denial of service issues      |
|                         | [CVE-2026-47319 CVE-2026-47320]           |
|                         |                                           |
| rsync=C2=A0[104]             | Reject excessively long HTTP proxy        =
|
|                         | response lines [CVE-2026-45232]           |
|                         |                                           |
| rtl-433=C2=A0[105]           | Fix buffer overflow issue [CVE-2025-      =
|
|                         | 34450]                                    |
|                         |                                           |
| ruby-css-parser=C2=A0[106]   | Fix validation of HTTPS certificates for  =
|
|                         | remote CSS [CVE-2026-44312]               |
|                         |                                           |
| rust-time=C2=A0[107]         | Fix denial of service [CVE-2026-25727]    =
|
|                         |                                           |
| samba=C2=A0[108]             | New upstream stable release               =
|
|                         |                                           |
| shim=C2=A0[109]              | New upstream release; build with default  =
|
|                         | gcc; set SBAT revocation level to         |
|                         | 2025021800                                |
|                         |                                           |
| shim-helpers-amd64-     | Update to shim 16.1-2~deb13u1             |
| signed=C2=A0[110]            |                                           =
|
|                         |                                           |
| shim-helpers-arm64-     | Update to shim 16.1-2~deb13u1             |
| signed=C2=A0[111]            |                                           =
|
|                         |                                           |
| shim-signed=C2=A0[112]       | Ensure Secure Boot compatibility with     =
|
|                         | 2023 Microsoft UEFI CA; check for likely  |
|                         | boot issues before installation; combine  |
|                         | and verify multiple shim signatures;      |
|                         | update signed shim binaries               |
|                         |                                           |
| skanpage=C2=A0[113]          | Fix data leakage issue [CVE-2025-55174]   =
|
|                         |                                           |
| smartdns=C2=A0[114]          | Fix buffer overflow issue [CVE-2026-1425] =
|
|                         |                                           |
| squirrel3=C2=A0[115]         | Fix sandbox escape [CVE-2021-41556]       =
|
|                         |                                           |
| sshfs-fuse=C2=A0[116]        | Add contain_symlinks option to prevent    =
|
|                         | symlink escape attacks [CVE-2026-47187];  |
|                         | reject hostname option injection via      |
|                         | bracketed mount source [CVE-2026-48711]   |
|                         |                                           |
| starman=C2=A0[117]           | Fix request smuggling issue [CVE-2026-    =
|
|                         | 40560]                                    |
|                         |                                           |
| symfony=C2=A0[118]           | Security update                           =
|
|                         |                                           |
| tigervnc=C2=A0[119]          | Prevent other users reading x0vncserver   =
|
|                         | screen [CVE-2026-34352]                   |
|                         |                                           |
| user-mode-linux=C2=A0[120]   | Rebuild with updated linux                =
|
|                         |                                           |
| vitrage=C2=A0[121]           | Fix remote code execution vulnerability   =
|
|                         | [CVE-2026-28370]                          |
|                         |                                           |
| wireless-regdb=C2=A0[122]    | New upstream stable release; update       =
|
|                         | regulatory information for several        |
|                         | countries                                 |
|                         |                                           |
| wireshark=C2=A0[123]         | New upstream stable release; fix denial   =
|
|                         | of service issue [CVE-2026-9759]          |
|                         |                                           |
| xz-utils=C2=A0[124]          | Fix buffer overflow issue [CVE-2026-      =
|
|                         | 34743]                                    |
|                         |                                           |
+-------------------------+-------------------------------------------+

    1: https://packages.debian.org/src:apache2
    2: https://packages.debian.org/src:archlinux-keyring
    3: https://packages.debian.org/src:awstats
    4: https://packages.debian.org/src:base-files
    5: https://packages.debian.org/src:beets
    6: https://packages.debian.org/src:calibre
    7: https://packages.debian.org/src:cdebootstrap
    8: https://packages.debian.org/src:chrony
    9: https://packages.debian.org/src:ckermit
   10: https://packages.debian.org/src:composer
   11: https://packages.debian.org/src:courier
   12: https://packages.debian.org/src:curl
   13: https://packages.debian.org/src:dar
   14: https://packages.debian.org/src:dcmtk
   15: https://packages.debian.org/src:debian-installer
   16: https://packages.debian.org/src:debian-installer-netboot-images
   17: https://packages.debian.org/src:debusine
   18: https://packages.debian.org/src:deepdiff
   19: https://packages.debian.org/src:dhcpcd
   20: https://packages.debian.org/src:distrobuilder
   21: https://packages.debian.org/src:dolphin
   22: https://packages.debian.org/src:errands
   23: https://packages.debian.org/src:execnet
   24: https://packages.debian.org/src:fldigi
   25: https://packages.debian.org/src:freecad
   26: https://packages.debian.org/src:fwupd
   27: https://packages.debian.org/src:gambas3
   28: https://packages.debian.org/src:gdown
   29: https://packages.debian.org/src:geoip
   30: https://packages.debian.org/src:geoip-database
   31: https://packages.debian.org/src:giflib
   32: https://packages.debian.org/src:gimp
   33: https://packages.debian.org/src:gnupg2
   34: https://packages.debian.org/src:gnustep-sqlclient
   35: https://packages.debian.org/src:graphite2
   36: https://packages.debian.org/src:horizon
   37: https://packages.debian.org/src:ironic
   38: https://packages.debian.org/src:isc-kea
   39: https://packages.debian.org/src:isenkram
   40: https://packages.debian.org/src:keystone
   41: https://packages.debian.org/src:libapache-session-browseable-perl
   42: https://packages.debian.org/src:libass
   43: https://packages.debian.org/src:libbytes-random-secure-perl
   44: https://packages.debian.org/src:libcaca
   45: https://packages.debian.org/src:libcrypt-pbkdf2-perl
   46: https://packages.debian.org/src:libcrypt-urandom-perl
   47: https://packages.debian.org/src:libhtml-parser-perl
   48: https://packages.debian.org/src:libnet-cidr-lite-perl
   49: https://packages.debian.org/src:libreoffice
   50: https://packages.debian.org/src:libslirp
   51: https://packages.debian.org/src:libtasn1-6
   52: https://packages.debian.org/src:libvncserver
   53: https://packages.debian.org/src:libxml-libxml-perl
   54: https://packages.debian.org/src:libxml2
   55: https://packages.debian.org/src:libxpm
   56: https://packages.debian.org/src:linuxcnc
   57: https://packages.debian.org/src:lxml-html-clean
   58: https://packages.debian.org/src:mesa
   59: https://packages.debian.org/src:miniupnpd
   60: https://packages.debian.org/src:modsecurity
   61: https://packages.debian.org/src:mutt
   62: https://packages.debian.org/src:mxml
   63: https://packages.debian.org/src:nbconvert
   64: https://packages.debian.org/src:neutron
   65: https://packages.debian.org/src:nss
   66: https://packages.debian.org/src:ojalgo
   67: https://packages.debian.org/src:opencc
   68: https://packages.debian.org/src:openslide
   69: https://packages.debian.org/src:php-guzzlehttp-psr7
   70: https://packages.debian.org/src:php-league-csv
   71: https://packages.debian.org/src:php-twig
   72: https://packages.debian.org/src:pillow
   73: https://packages.debian.org/src:poco
   74: https://packages.debian.org/src:poetry
   75: https://packages.debian.org/src:poppler
   76: https://packages.debian.org/src:postfix
   77: https://packages.debian.org/src:protobuf
   78: https://packages.debian.org/src:psd-tools
   79: https://packages.debian.org/src:pupnp
   80: https://packages.debian.org/src:pymdown-extensions
   81: https://packages.debian.org/src:pyopenssl
   82: https://packages.debian.org/src:pytest-httpbin
   83: https://packages.debian.org/src:python-daphne
   84: https://packages.debian.org/src:python-django
   85: https://packages.debian.org/src:python-dynaconf
   86: https://packages.debian.org/src:python-grpc-tools
   87: https://packages.debian.org/src:python-handy-archives
   88: https://packages.debian.org/src:python-idna
   89: https://packages.debian.org/src:python-iniparse
   90: https://packages.debian.org/src:python-jwcrypto
   91: https://packages.debian.org/src:python-markdown
   92: https://packages.debian.org/src:python-marshmallow
   93: https://packages.debian.org/src:python-memray
   94: https://packages.debian.org/src:python-virtualenv
   95: https://packages.debian.org/src:python-webob
   96: https://packages.debian.org/src:python-xmltodict
   97: https://packages.debian.org/src:python3.13
   98: https://packages.debian.org/src:qemu
   99: https://packages.debian.org/src:qtmir
  100: https://packages.debian.org/src:rauc
  101: https://packages.debian.org/src:resource-agents
  102: https://packages.debian.org/src:rhino
  103: https://packages.debian.org/src:rlottie
  104: https://packages.debian.org/src:rsync
  105: https://packages.debian.org/src:rtl-433
  106: https://packages.debian.org/src:ruby-css-parser
  107: https://packages.debian.org/src:rust-time
  108: https://packages.debian.org/src:samba
  109: https://packages.debian.org/src:shim
  110: https://packages.debian.org/src:shim-helpers-amd64-signed
  111: https://packages.debian.org/src:shim-helpers-arm64-signed
  112: https://packages.debian.org/src:shim-signed
  113: https://packages.debian.org/src:skanpage
  114: https://packages.debian.org/src:smartdns
  115: https://packages.debian.org/src:squirrel3
  116: https://packages.debian.org/src:sshfs-fuse
  117: https://packages.debian.org/src:starman
  118: https://packages.debian.org/src:symfony
  119: https://packages.debian.org/src:tigervnc
  120: https://packages.debian.org/src:user-mode-linux
  121: https://packages.debian.org/src:vitrage
  122: https://packages.debian.org/src:wireless-regdb
  123: https://packages.debian.org/src:wireshark
  124: https://packages.debian.org/src:xz-utils

Security Updates
----------------

This revision adds the following security updates to the stable release.
The Security Team has already released an advisory for each of these
updates:

+----------------+--------------------------------+
| Advisory ID    | Package                        |
+----------------+--------------------------------+
| DSA-6250=C2=A0[125] | chromium=C2=A0[126]                 |
|                |                                |
| DSA-6256=C2=A0[127] | php8.4=C2=A0[128]                   |
|                |                                |
| DSA-6266=C2=A0[129] | nghttp2=C2=A0[130]                  |
|                |                                |
| DSA-6267=C2=A0[131] | thunderbird=C2=A0[132]              |
|                |                                |
| DSA-6268=C2=A0[133] | ffmpeg=C2=A0[134]                   |
|                |                                |
| DSA-6270=C2=A0[135] | postgresql-17=C2=A0[136]            |
|                |                                |
| DSA-6271=C2=A0[137] | gsasl=C2=A0[138]                    |
|                |                                |
| DSA-6273=C2=A0[139] | chromium=C2=A0[140]                 |
|                |                                |
| DSA-6274=C2=A0[141] | linux-signed-amd64=C2=A0[142]       |
|                |                                |
| DSA-6274=C2=A0[143] | linux-signed-arm64=C2=A0[144]       |
|                |                                |
| DSA-6274=C2=A0[145] | linux=C2=A0[146]                    |
|                |                                |
| DSA-6277=C2=A0[147] | openjpeg2=C2=A0[148]                |
|                |                                |
| DSA-6278=C2=A0[149] | nginx=C2=A0[150]                    |
|                |                                |
| DSA-6279=C2=A0[151] | redis=C2=A0[152]                    |
|                |                                |
| DSA-6280=C2=A0[153] | netatalk=C2=A0[154]                 |
|                |                                |
| DSA-6281=C2=A0[155] | gnutls28=C2=A0[156]                 |
|                |                                |
| DSA-6282=C2=A0[157] | rsync=C2=A0[158]                    |
|                |                                |
| DSA-6283=C2=A0[159] | firefox-esr=C2=A0[160]              |
|                |                                |
| DSA-6284=C2=A0[161] | pdns=C2=A0[162]                     |
|                |                                |
| DSA-6285=C2=A0[163] | bind9=C2=A0[164]                    |
|                |                                |
| DSA-6286=C2=A0[165] | evince=C2=A0[166]                   |
|                |                                |
| DSA-6287=C2=A0[167] | chromium=C2=A0[168]                 |
|                |                                |
| DSA-6288=C2=A0[169] | thunderbird=C2=A0[170]              |
|                |                                |
| DSA-6289=C2=A0[171] | openvpn=C2=A0[172]                  |
|                |                                |
| DSA-6290=C2=A0[173] | nss=C2=A0[174]                      |
|                |                                |
| DSA-6291=C2=A0[175] | haproxy=C2=A0[176]                  |
|                |                                |
| DSA-6292=C2=A0[177] | haveged=C2=A0[178]                  |
|                |                                |
| DSA-6293=C2=A0[179] | krb5=C2=A0[180]                     |
|                |                                |
| DSA-6294=C2=A0[181] | libgcrypt20=C2=A0[182]              |
|                |                                |
| DSA-6295=C2=A0[183] | linux-signed-amd64=C2=A0[184]       |
|                |                                |
| DSA-6295=C2=A0[185] | linux-signed-arm64=C2=A0[186]       |
|                |                                |
| DSA-6295=C2=A0[187] | linux=C2=A0[188]                    |
|                |                                |
| DSA-6296=C2=A0[189] | spip=C2=A0[190]                     |
|                |                                |
| DSA-6297=C2=A0[191] | samba=C2=A0[192]                    |
|                |                                |
| DSA-6298=C2=A0[193] | imagemagick=C2=A0[194]              |
|                |                                |
| DSA-6299=C2=A0[195] | kdenlive=C2=A0[196]                 |
|                |                                |
| DSA-6300=C2=A0[197] | node-shell-quote=C2=A0[198]         |
|                |                                |
| DSA-6301=C2=A0[199] | roundcube=C2=A0[200]                |
|                |                                |
| DSA-6302=C2=A0[201] | starlette=C2=A0[202]                |
|                |                                |
| DSA-6303=C2=A0[203] | varnish=C2=A0[204]                  |
|                |                                |
| DSA-6304=C2=A0[205] | unbound=C2=A0[206]                  |
|                |                                |
| DSA-6305=C2=A0[207] | linux-signed-amd64=C2=A0[208]       |
|                |                                |
| DSA-6305=C2=A0[209] | linux-signed-arm64=C2=A0[210]       |
|                |                                |
| DSA-6305=C2=A0[211] | linux=C2=A0[212]                    |
|                |                                |
| DSA-6307=C2=A0[213] | kitty=C2=A0[214]                    |
|                |                                |
| DSA-6308=C2=A0[215] | nagios4=C2=A0[216]                  |
|                |                                |
| DSA-6309=C2=A0[217] | exim4=C2=A0[218]                    |
|                |                                |
| DSA-6311=C2=A0[219] | php-twig=C2=A0[220]                 |
|                |                                |
| DSA-6312=C2=A0[221] | symfony=C2=A0[222]                  |
|                |                                |
| DSA-6313=C2=A0[223] | dovecot=C2=A0[224]                  |
|                |                                |
| DSA-6314=C2=A0[225] | swift=C2=A0[226]                    |
|                |                                |
| DSA-6315=C2=A0[227] | cyborg=C2=A0[228]                   |
|                |                                |
| DSA-6316=C2=A0[229] | chromium=C2=A0[230]                 |
|                |                                |
| DSA-6318=C2=A0[231] | gst-plugins-good1.0=C2=A0[232]      |
|                |                                |
| DSA-6319=C2=A0[233] | yelp=C2=A0[234]                     |
|                |                                |
| DSA-6321=C2=A0[235] | ceph=C2=A0[236]                     |
|                |                                |
| DSA-6322=C2=A0[237] | frr=C2=A0[238]                      |
|                |                                |
| DSA-6323=C2=A0[239] | apache2=C2=A0[240]                  |
|                |                                |
| DSA-6324=C2=A0[241] | request-tracker5=C2=A0[242]         |
|                |                                |
| DSA-6325=C2=A0[243] | chromium=C2=A0[244]                 |
|                |                                |
| DSA-6326=C2=A0[245] | nginx=C2=A0[246]                    |
|                |                                |
| DSA-6328=C2=A0[247] | tomcat10=C2=A0[248]                 |
|                |                                |
| DSA-6329=C2=A0[249] | tomcat11=C2=A0[250]                 |
|                |                                |
| DSA-6330=C2=A0[251] | strongswan=C2=A0[252]               |
|                |                                |
| DSA-6331=C2=A0[253] | keystone=C2=A0[254]                 |
|                |                                |
| DSA-6332=C2=A0[255] | okular=C2=A0[256]                   |
|                |                                |
| DSA-6333=C2=A0[257] | mistral=C2=A0[258]                  |
|                |                                |
| DSA-6334=C2=A0[259] | poppler=C2=A0[260]                  |
|                |                                |
| DSA-6335=C2=A0[261] | openssl=C2=A0[262]                  |
|                |                                |
| DSA-6336=C2=A0[263] | jackson-core=C2=A0[264]             |
|                |                                |
| DSA-6336=C2=A0[265] | jackson-databind=C2=A0[266]         |
|                |                                |
| DSA-6336=C2=A0[267] | jackson-dataformat-smile=C2=A0[268] |
|                |                                |
| DSA-6337=C2=A0[269] | chromium=C2=A0[270]                 |
|                |                                |
| DSA-6338=C2=A0[271] | libdbi-perl=C2=A0[272]              |
|                |                                |
| DSA-6339=C2=A0[273] | libinput=C2=A0[274]                 |
|                |                                |
| DSA-6340=C2=A0[275] | neutron=C2=A0[276]                  |
|                |                                |
| DSA-6341=C2=A0[277] | ironic=C2=A0[278]                   |
|                |                                |
| DSA-6341=C2=A0[279] | python-oslo.messaging=C2=A0[280]    |
|                |                                |
| DSA-6342=C2=A0[281] | jpeg-xl=C2=A0[282]                  |
|                |                                |
| DSA-6343=C2=A0[283] | librabbitmq=C2=A0[284]              |
|                |                                |
| DSA-6344=C2=A0[285] | chromium=C2=A0[286]                 |
|                |                                |
| DSA-6345=C2=A0[287] | libgd-perl=C2=A0[288]               |
|                |                                |
| DSA-6346=C2=A0[289] | libreoffice=C2=A0[290]              |
|                |                                |
| DSA-6347=C2=A0[291] | bird2=C2=A0[292]                    |
|                |                                |
| DSA-6348=C2=A0[293] | gsasl=C2=A0[294]                    |
|                |                                |
| DSA-6349=C2=A0[295] | atril=C2=A0[296]                    |
|                |                                |
| DSA-6350=C2=A0[297] | firefox-esr=C2=A0[298]              |
|                |                                |
| DSA-6351=C2=A0[299] | thunderbird=C2=A0[300]              |
|                |                                |
| DSA-6352=C2=A0[301] | chromium=C2=A0[302]                 |
|                |                                |
| DSA-6353=C2=A0[303] | gst-libav1.0=C2=A0[304]             |
|                |                                |
| DSA-6354=C2=A0[305] | libconfig-inifiles-perl=C2=A0[306]  |
|                |                                |
| DSA-6355=C2=A0[307] | linux-signed-amd64=C2=A0[308]       |
|                |                                |
| DSA-6355=C2=A0[309] | linux-signed-arm64=C2=A0[310]       |
|                |                                |
| DSA-6355=C2=A0[311] | linux=C2=A0[312]                    |
|                |                                |
| DSA-6356=C2=A0[313] | imagemagick=C2=A0[314]              |
|                |                                |
| DSA-6357=C2=A0[315] | pillow=C2=A0[316]                   |
|                |                                |
| DSA-6358=C2=A0[317] | libhttp-daemon-perl=C2=A0[318]      |
|                |                                |
| DSA-6359=C2=A0[319] | gst-plugins-good1.0=C2=A0[320]      |
|                |                                |
| DSA-6360=C2=A0[321] | squid=C2=A0[322]                    |
|                |                                |
| DSA-6361=C2=A0[323] | ffmpeg=C2=A0[324]                   |
|                |                                |
| DSA-6362=C2=A0[325] | gst-plugins-bad1.0=C2=A0[326]       |
|                |                                |
| DSA-6363=C2=A0[327] | python-urllib3=C2=A0[328]           |
|                |                                |
| DSA-6364=C2=A0[329] | chromium=C2=A0[330]                 |
|                |                                |
| DSA-6365=C2=A0[331] | libssh2=C2=A0[332]                  |
|                |                                |
| DSA-6366=C2=A0[333] | sogo=C2=A0[334]                     |
|                |                                |
| DSA-6367=C2=A0[335] | dnsdist=C2=A0[336]                  |
|                |                                |
| DSA-6368=C2=A0[337] | pdns=C2=A0[338]                     |
|                |                                |
| DSA-6369=C2=A0[339] | pdns-recursor=C2=A0[340]            |
|                |                                |
| DSA-6370=C2=A0[341] | incus=C2=A0[342]                    |
|                |                                |
| DSA-6371=C2=A0[343] | xorg-server=C2=A0[344]              |
|                |                                |
| DSA-6372=C2=A0[345] | tor=C2=A0[346]                      |
|                |                                |
| DSA-6373=C2=A0[347] | lxd=C2=A0[348]                      |
|                |                                |
| DSA-6374=C2=A0[349] | nginx=C2=A0[350]                    |
|                |                                |
| DSA-6375=C2=A0[351] | fastnetmon=C2=A0[352]               |
|                |                                |
| DSA-6376=C2=A0[353] | openvpn=C2=A0[354]                  |
|                |                                |
| DSA-6377=C2=A0[355] | php8.4=C2=A0[356]                   |
|                |                                |
| DSA-6378=C2=A0[357] | chromium=C2=A0[358]                 |
|                |                                |
| DSA-6379=C2=A0[359] | bird3=C2=A0[360]                    |
|                |                                |
| DSA-6380=C2=A0[361] | mediawiki=C2=A0[362]                |
|                |                                |
| DSA-6384=C2=A0[363] | chromium=C2=A0[364]                 |
|                |                                |
+----------------+--------------------------------+

  125: https://www.debian.org/security/2026/dsa-6250
  126: https://packages.debian.org/src:chromium
  127: https://www.debian.org/security/2026/dsa-6256
  128: https://packages.debian.org/src:php8.4
  129: https://www.debian.org/security/2026/dsa-6266
  130: https://packages.debian.org/src:nghttp2
  131: https://www.debian.org/security/2026/dsa-6267
  132: https://packages.debian.org/src:thunderbird
  133: https://www.debian.org/security/2026/dsa-6268
  134: https://packages.debian.org/src:ffmpeg
  135: https://www.debian.org/security/2026/dsa-6270
  136: https://packages.debian.org/src:postgresql-17
  137: https://www.debian.org/security/2026/dsa-6271
  138: https://packages.debian.org/src:gsasl
  139: https://www.debian.org/security/2026/dsa-6273
  140: https://packages.debian.org/src:chromium
  141: https://www.debian.org/security/2026/dsa-6274
  142: https://packages.debian.org/src:linux-signed-amd64
  143: https://www.debian.org/security/2026/dsa-6274
  144: https://packages.debian.org/src:linux-signed-arm64
  145: https://www.debian.org/security/2026/dsa-6274
  146: https://packages.debian.org/src:linux
  147: https://www.debian.org/security/2026/dsa-6277
  148: https://packages.debian.org/src:openjpeg2
  149: https://www.debian.org/security/2026/dsa-6278
  150: https://packages.debian.org/src:nginx
  151: https://www.debian.org/security/2026/dsa-6279
  152: https://packages.debian.org/src:redis
  153: https://www.debian.org/security/2026/dsa-6280
  154: https://packages.debian.org/src:netatalk
  155: https://www.debian.org/security/2026/dsa-6281
  156: https://packages.debian.org/src:gnutls28
  157: https://www.debian.org/security/2026/dsa-6282
  158: https://packages.debian.org/src:rsync
  159: https://www.debian.org/security/2026/dsa-6283
  160: https://packages.debian.org/src:firefox-esr
  161: https://www.debian.org/security/2026/dsa-6284
  162: https://packages.debian.org/src:pdns
  163: https://www.debian.org/security/2026/dsa-6285
  164: https://packages.debian.org/src:bind9
  165: https://www.debian.org/security/2026/dsa-6286
  166: https://packages.debian.org/src:evince
  167: https://www.debian.org/security/2026/dsa-6287
  168: https://packages.debian.org/src:chromium
  169: https://www.debian.org/security/2026/dsa-6288
  170: https://packages.debian.org/src:thunderbird
  171: https://www.debian.org/security/2026/dsa-6289
  172: https://packages.debian.org/src:openvpn
  173: https://www.debian.org/security/2026/dsa-6290
  174: https://packages.debian.org/src:nss
  175: https://www.debian.org/security/2026/dsa-6291
  176: https://packages.debian.org/src:haproxy
  177: https://www.debian.org/security/2026/dsa-6292
  178: https://packages.debian.org/src:haveged
  179: https://www.debian.org/security/2026/dsa-6293
  180: https://packages.debian.org/src:krb5
  181: https://www.debian.org/security/2026/dsa-6294
  182: https://packages.debian.org/src:libgcrypt20
  183: https://www.debian.org/security/2026/dsa-6295
  184: https://packages.debian.org/src:linux-signed-amd64
  185: https://www.debian.org/security/2026/dsa-6295
  186: https://packages.debian.org/src:linux-signed-arm64
  187: https://www.debian.org/security/2026/dsa-6295
  188: https://packages.debian.org/src:linux
  189: https://www.debian.org/security/2026/dsa-6296
  190: https://packages.debian.org/src:spip
  191: https://www.debian.org/security/2026/dsa-6297
  192: https://packages.debian.org/src:samba
  193: https://www.debian.org/security/2026/dsa-6298
  194: https://packages.debian.org/src:imagemagick
  195: https://www.debian.org/security/2026/dsa-6299
  196: https://packages.debian.org/src:kdenlive
  197: https://www.debian.org/security/2026/dsa-6300
  198: https://packages.debian.org/src:node-shell-quote
  199: https://www.debian.org/security/2026/dsa-6301
  200: https://packages.debian.org/src:roundcube
  201: https://www.debian.org/security/2026/dsa-6302
  202: https://packages.debian.org/src:starlette
  203: https://www.debian.org/security/2026/dsa-6303
  204: https://packages.debian.org/src:varnish
  205: https://www.debian.org/security/2026/dsa-6304
  206: https://packages.debian.org/src:unbound
  207: https://www.debian.org/security/2026/dsa-6305
  208: https://packages.debian.org/src:linux-signed-amd64
  209: https://www.debian.org/security/2026/dsa-6305
  210: https://packages.debian.org/src:linux-signed-arm64
  211: https://www.debian.org/security/2026/dsa-6305
  212: https://packages.debian.org/src:linux
  213: https://www.debian.org/security/2026/dsa-6307
  214: https://packages.debian.org/src:kitty
  215: https://www.debian.org/security/2026/dsa-6308
  216: https://packages.debian.org/src:nagios4
  217: https://www.debian.org/security/2026/dsa-6309
  218: https://packages.debian.org/src:exim4
  219: https://www.debian.org/security/2026/dsa-6311
  220: https://packages.debian.org/src:php-twig
  221: https://www.debian.org/security/2026/dsa-6312
  222: https://packages.debian.org/src:symfony
  223: https://www.debian.org/security/2026/dsa-6313
  224: https://packages.debian.org/src:dovecot
  225: https://www.debian.org/security/2026/dsa-6314
  226: https://packages.debian.org/src:swift
  227: https://www.debian.org/security/2026/dsa-6315
  228: https://packages.debian.org/src:cyborg
  229: https://www.debian.org/security/2026/dsa-6316
  230: https://packages.debian.org/src:chromium
  231: https://www.debian.org/security/2026/dsa-6318
  232: https://packages.debian.org/src:gst-plugins-good1.0
  233: https://www.debian.org/security/2026/dsa-6319
  234: https://packages.debian.org/src:yelp
  235: https://www.debian.org/security/2026/dsa-6321
  236: https://packages.debian.org/src:ceph
  237: https://www.debian.org/security/2026/dsa-6322
  238: https://packages.debian.org/src:frr
  239: https://www.debian.org/security/2026/dsa-6323
  240: https://packages.debian.org/src:apache2
  241: https://www.debian.org/security/2026/dsa-6324
  242: https://packages.debian.org/src:request-tracker5
  243: https://www.debian.org/security/2026/dsa-6325
  244: https://packages.debian.org/src:chromium
  245: https://www.debian.org/security/2026/dsa-6326
  246: https://packages.debian.org/src:nginx
  247: https://www.debian.org/security/2026/dsa-6328
  248: https://packages.debian.org/src:tomcat10
  249: https://www.debian.org/security/2026/dsa-6329
  250: https://packages.debian.org/src:tomcat11
  251: https://www.debian.org/security/2026/dsa-6330
  252: https://packages.debian.org/src:strongswan
  253: https://www.debian.org/security/2026/dsa-6331
  254: https://packages.debian.org/src:keystone
  255: https://www.debian.org/security/2026/dsa-6332
  256: https://packages.debian.org/src:okular
  257: https://www.debian.org/security/2026/dsa-6333
  258: https://packages.debian.org/src:mistral
  259: https://www.debian.org/security/2026/dsa-6334
  260: https://packages.debian.org/src:poppler
  261: https://www.debian.org/security/2026/dsa-6335
  262: https://packages.debian.org/src:openssl
  263: https://www.debian.org/security/2026/dsa-6336
  264: https://packages.debian.org/src:jackson-core
  265: https://www.debian.org/security/2026/dsa-6336
  266: https://packages.debian.org/src:jackson-databind
  267: https://www.debian.org/security/2026/dsa-6336
  268: https://packages.debian.org/src:jackson-dataformat-smile
  269: https://www.debian.org/security/2026/dsa-6337
  270: https://packages.debian.org/src:chromium
  271: https://www.debian.org/security/2026/dsa-6338
  272: https://packages.debian.org/src:libdbi-perl
  273: https://www.debian.org/security/2026/dsa-6339
  274: https://packages.debian.org/src:libinput
  275: https://www.debian.org/security/2026/dsa-6340
  276: https://packages.debian.org/src:neutron
  277: https://www.debian.org/security/2026/dsa-6341
  278: https://packages.debian.org/src:ironic
  279: https://www.debian.org/security/2026/dsa-6341
  280: https://packages.debian.org/src:python-oslo.messaging
  281: https://www.debian.org/security/2026/dsa-6342
  282: https://packages.debian.org/src:jpeg-xl
  283: https://www.debian.org/security/2026/dsa-6343
  284: https://packages.debian.org/src:librabbitmq
  285: https://www.debian.org/security/2026/dsa-6344
  286: https://packages.debian.org/src:chromium
  287: https://www.debian.org/security/2026/dsa-6345
  288: https://packages.debian.org/src:libgd-perl
  289: https://www.debian.org/security/2026/dsa-6346
  290: https://packages.debian.org/src:libreoffice
  291: https://www.debian.org/security/2026/dsa-6347
  292: https://packages.debian.org/src:bird2
  293: https://www.debian.org/security/2026/dsa-6348
  294: https://packages.debian.org/src:gsasl
  295: https://www.debian.org/security/2026/dsa-6349
  296: https://packages.debian.org/src:atril
  297: https://www.debian.org/security/2026/dsa-6350
  298: https://packages.debian.org/src:firefox-esr
  299: https://www.debian.org/security/2026/dsa-6351
  300: https://packages.debian.org/src:thunderbird
  301: https://www.debian.org/security/2026/dsa-6352
  302: https://packages.debian.org/src:chromium
  303: https://www.debian.org/security/2026/dsa-6353
  304: https://packages.debian.org/src:gst-libav1.0
  305: https://www.debian.org/security/2026/dsa-6354
  306: https://packages.debian.org/src:libconfig-inifiles-perl
  307: https://www.debian.org/security/2026/dsa-6355
  308: https://packages.debian.org/src:linux-signed-amd64
  309: https://www.debian.org/security/2026/dsa-6355
  310: https://packages.debian.org/src:linux-signed-arm64
  311: https://www.debian.org/security/2026/dsa-6355
  312: https://packages.debian.org/src:linux
  313: https://www.debian.org/security/2026/dsa-6356
  314: https://packages.debian.org/src:imagemagick
  315: https://www.debian.org/security/2026/dsa-6357
  316: https://packages.debian.org/src:pillow
  317: https://www.debian.org/security/2026/dsa-6358
  318: https://packages.debian.org/src:libhttp-daemon-perl
  319: https://www.debian.org/security/2026/dsa-6359
  320: https://packages.debian.org/src:gst-plugins-good1.0
  321: https://www.debian.org/security/2026/dsa-6360
  322: https://packages.debian.org/src:squid
  323: https://www.debian.org/security/2026/dsa-6361
  324: https://packages.debian.org/src:ffmpeg
  325: https://www.debian.org/security/2026/dsa-6362
  326: https://packages.debian.org/src:gst-plugins-bad1.0
  327: https://www.debian.org/security/2026/dsa-6363
  328: https://packages.debian.org/src:python-urllib3
  329: https://www.debian.org/security/2026/dsa-6364
  330: https://packages.debian.org/src:chromium
  331: https://www.debian.org/security/2026/dsa-6365
  332: https://packages.debian.org/src:libssh2
  333: https://www.debian.org/security/2026/dsa-6366
  334: https://packages.debian.org/src:sogo
  335: https://www.debian.org/security/2026/dsa-6367
  336: https://packages.debian.org/src:dnsdist
  337: https://www.debian.org/security/2026/dsa-6368
  338: https://packages.debian.org/src:pdns
  339: https://www.debian.org/security/2026/dsa-6369
  340: https://packages.debian.org/src:pdns-recursor
  341: https://www.debian.org/security/2026/dsa-6370
  342: https://packages.debian.org/src:incus
  343: https://www.debian.org/security/2026/dsa-6371
  344: https://packages.debian.org/src:xorg-server
  345: https://www.debian.org/security/2026/dsa-6372
  346: https://packages.debian.org/src:tor
  347: https://www.debian.org/security/2026/dsa-6373
  348: https://packages.debian.org/src:lxd
  349: https://www.debian.org/security/2026/dsa-6374
  350: https://packages.debian.org/src:nginx
  351: https://www.debian.org/security/2026/dsa-6375
  352: https://packages.debian.org/src:fastnetmon
  353: https://www.debian.org/security/2026/dsa-6376
  354: https://packages.debian.org/src:openvpn
  355: https://www.debian.org/security/2026/dsa-6377
  356: https://packages.debian.org/src:php8.4
  357: https://www.debian.org/security/2026/dsa-6378
  358: https://packages.debian.org/src:chromium
  359: https://www.debian.org/security/2026/dsa-6379
  360: https://packages.debian.org/src:bird3
  361: https://www.debian.org/security/2026/dsa-6380
  362: https://packages.debian.org/src:mediawiki
  363: https://www.debian.org/security/2026/dsa-6384
  364: https://packages.debian.org/src:chromium

Debian Installer
----------------

The installer has been updated to include the fixes incorporated into
stable by the point release.


URLs
----

The complete lists of packages that have changed with this revision:

https://deb.debian.org/debian/dists/trixie/ChangeLog


The current stable distribution:

https://deb.debian.org/debian/dists/stable/


Proposed updates to the stable distribution:

https://deb.debian.org/debian/dists/proposed-updates


stable distribution information (release notes, errata etc.):

https://www.debian.org/releases/stable/


Security announcements and information:

https://www.debian.org/security/



About Debian
------------

The Debian Project is an association of Free Software developers who
volunteer their time and effort in order to produce the completely free
operating system Debian.


Contact Information
-------------------

For further information, please visit the Debian web pages at
https://www.debian.org/, send mail to <[email protected]>, or contact the
stable release team at <[email protected]>.

--=-Je7Wie/A9xqEGmXLpcs1
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part

-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEEcH/R3vmpi4JWBoDfeBP2a44wMXIFAmpSMqMACgkQeBP2a44w
MXL7cQ//QU8nB867b1sDC0gt4DEe3orXuTo/ajUelqwfe0voHaHpa01gcf4Xf+Ht
YFEQLq7fP9uAhEuOXE11+j9w1/Kd2zsVE+3+e1PSJi0RcoCqp+PoYl7oT5SeajyG
5A7LeQxPKTxLW+FWUMGys8Do7AHMWXmgkHBfpsir4eMhxJwyFWfR+SO3B1ypcs+c
r9VukiOC9jfQyR+BALApQhvOf1eAgaRwcUlYdxcR2qVdpOmuDZItz9ruTha7PBfK
SlA3PnM3U4mGg0muJR24Gw3+Yi1Dv+Z/yiYc95pR70E3UJUV6CP+K+bVQ6Z4yfCj
hfS7lFDUjotM/FHLEy/VLto1izTuE7g11ylRENta8TGemK2zJOzZzI/+2D1pbZaT
pPzhHBLuMWKeZ44gqjmUlTDA9r+vLtU9wv2S9GVZcZ9Coew2DWoekuej7RiCtB7R
3w99fSjGcUpmKRHWko1FCgPjpe12GNxutMFMWiX+Vf7N/PJNWLY2X4E970S4kPnC
rnrS3U9pAmtEV8W4MCv/45Hqw968d8OMXuDdBuPtn+B79NN3ZrqOCZEIDzjETbgv
VOgW8WXhvnWU65ZdTRRpbnXlPooM6uCAE2E7w2eKwr9UAlHzECNMMP3Jkz6+MpDO
JowQ9ZB/wXLCvqerc+9wf0ZF5Kn7xIpK7IvotEGRCRWwL6FJNEw=
=vIq6
-----END PGP SIGNATURE-----

--=-Je7Wie/A9xqEGmXLpcs1--