Debian 13.7 Security Fixes and Package Updates Address 92 Advisories, 106 Packages

www.news4hackers.com-debian-13-7-security-fixes-and-package-updates-address-92-advisories-106-packages-debian-13-7-security-fixes-and-package-updates-address-92-advisories-106-packages

The Debian project released version 13.7, codenamed trixie, incorporating 92 previously published security advisories.

Debian 13.7 Integrates 92 Security Patches Across 106 Updated Packages

The Debian project released version 13.7, codenamed trixie, incorporating 92 previously published security advisories. This update includes corrections for 106 source packages and a rebuilt installer. Six of the advisories specifically address the Linux kernel, with each tied to the linux source package and signed builds for amd64 and arm64 architectures. These include DSA-6381, DSA-6393, DSA-6405, DSA-6415, DSA-6466, and DSA-6477. Users installing from older trixie media will receive updated package versions during their first system update. Systems configured to track security.debian.org will experience minimal package changes, as most security updates are already included in this release.

Critical Vulnerabilities Addressed

The update resolves a significant number of vulnerabilities across multiple software components. The qemu package contains 25 reported issues, while imagemagick addresses 24, wolfssl 15, and perl 13. The cyrus-imapd component includes nine CVEs, primarily related to insufficient access controls and an out-of-bounds read. The mbedtls library features seven vulnerabilities, including a client impersonation flaw (CVE-2026-34873) and a signature algorithm injection vulnerability (CVE-2026-25834).

Bootloader and Firmware Fixes

The u-boot bootloader received two critical updates. One resolves a flaw (CVE-2026-46728) where the FIT image verification process incorrectly accepted invalid files. Another addresses a buffer overread in BOOTP/DHCP interactions (CVE-2024-42040), a two-year-old issue. The qemu project also includes a secure boot bypass (CVE-2026-16288) and a UEFI device post-load check (CVE-2026-61404). The sbsigntool utility, used for signing EFI binaries, now corrects intermediate certificate validation.

Credential and Network Security Enhancements

The perl and libhttp-tiny-perl packages fix a credential forwarding vulnerability (CVE-2026-7017) that could expose authentication headers during HTTP redirects. Both also address CRLF validation issues (CVE-2026-7010). The flask framework now implements the Vary: Cookie header to prevent cache poisoning when session data is accessed. The dhcpcd utility mitigates an IPv6 router advertisement flaw (CVE-2026-14258), while dnsmasq resolves a buffer overflow (CVE-2026-12725) and an out-of-bounds read (CVE-2026-12969).

Language and Library Updates

The python3.13 package includes a fix for a use-after-free error in dict.clear() caused by embedded values, a regression from prior versions. Additional CVEs in this category include a file overwrite vulnerability (CVE-2026-11940) and improper handling of user and group IDs in tar files (CVE-2026-4360). The bettercap tool no longer installs its systemd service by default and addresses a remote denial-of-service vulnerability (CVE-2026-8276) in its mysql.server module. Onionshare prevents file writes in Receive mode when uploads are disabled (CVE-2026-54707).

Update Deployment Details

The Debian installer now includes the point release fixes, with the kernel ABI updated to 6.12.107+deb13. Existing systems can apply the update by configuring their package manager to access a Debian mirror. This release ensures systems remain protected against the identified vulnerabilities through comprehensive patching.

According to the Debian project, “This release ensures systems remain protected against the identified vulnerabilities through comprehensive patching.”


Blog Image

About Author

en_USEnglish