----------------------------------------------------------------------------
Debian Stable Updates Announcement SUA 286-1         https://www.debian.org/
[email protected]                              Adam D. Barratt
September 7th, 2026
----------------------------------------------------------------------------

Upcoming Debian 13 Update (13.7)

An update to Debian 13 is scheduled for Saturday, September 12th, 2026. As
of now it will include the following bug fixes. They can be found in
"trixie-proposed-updates", which is carried by all official mirrors.

Please note that packages published through security.debian.org are not
listed, but will be included if possible. Some of the updates below are also
already available through "trixie-updates".

Testing and feedback would be appreciated. Bugs should be filed in the
Debian Bug Tracking System, but please make the Release Team aware of them
by copying "[email protected]" on your mails.

The point release will also include a rebuild of debian-installer.


Miscellaneous Bugfixes
----------------------

This stable update adds a few important corrections to the following
packages:

  Package                    Reason
  -------                    ------

  akonadi-search             Fix crash with empty input

  alsa-lib                   Fix heap overflow issue [CVE-2026-25068]

  ansible-core               New upstream stable release; fix arbitrary code
                             injection issue [CVE-2026-11332]

  at-spi2-core               Fix atkversion.h header for C++ linkage

  audit                      Add support for the riscv64 architecture

  auto-apt-proxy             Prevent apt-helper call from recursing into
                             auto-apt-proxy; wait for network to be online

  awffull                    Fix visit / page statistics

  base-files                 Update for the point release; add AGPL-3.0,
                             Artistic-2.0, BSL-1.0, CC-BY-3.0, CC-BY-4.0,
                             CC-BY-SA-3.0, CC-BY-SA-4.0, GFDL-1.1 and
                             OFL-1.1 to common-licenses

  bash                       Rebuild with updated glibc

  bcg729                     Fix division by zero

  bettercap                  Fix mysql.server module remote DoS via crafted
                             client handshake [CVE-2026-8276]; stop
                             installing systemd service by default

  bglibs                     Rebuild with updated glibc

  binwalk                    Fix path traversal issue [CVE-2026-7179]

  busybox                    Rebuild with updated glibc

  catatonit                  Rebuild with updated glibc

  cdebootstrap               Rebuild with updated glibc

  chkrootkit                 Rebuild with updated glibc

  cinnamon                   Fix download and update of spices (applets,
                             desklets, extensions and themes)

  condor                     Rebuild with updated glibc

  curl                       Fix OpenSSL engine loading return value; remove
                             trailing whitespaces causing test failures

  cyrus-imapd                Allow JMAP EventSource without WebSocket/wslay;
                             fix insufficient access check issues
                             [CVE-2026-47084 CVE-2026-47086 CVE-2026-47087
                             CVE-2026-47081 CVE-2026-47089 CVE-2026-47085
                             CVE-2026-47083 CVE-2026-47082]; fix out of
                             bounds read issue [CVE-2026-47088]

  dar                        Rebuild with updated glibc; rebuild with
                             updated curl; fix glibc Built-Using regression

  dcmtk                      Fix denial of service issues [CVE-2026-35505
                             CVE-2026-44628 CVE-2026-50254]; fix path
                             traversal issues [CVE-2026-50003
                             CVE-2026-52868]

  debian-edu-install         Skip Icinga 2 IDO MySQL dbconfig setup

  dhcpcd                     Fix IPv6 Neighbor Discovery option parsing to
                             discard advertisements with zero-length options
                             [CVE-2026-14258]

  dnsmasq                    Fix buffer overflow issue [CVE-2026-12725]; fix
                             out of bounds read issue [CVE-2026-12969]

  docker.io                  Rebuild with updated glibc

  flask                      Ensure Vary: Cookie is set on session access
                             [CVE-2026-27205]

  fluidsynth                 Fix buffer overflow issues [CVE-2026-58264
                             CVE-2026-61714]

  glib2.0                    Fix out of bounds access issues [CVE-2026-58010
                             CVE-2026-58011 CVE-2026-58012 CVE-2026-58013
                             CVE-2026-58014]; fix file content disclosure
                             issue [CVE-2026-58015]; fix denial of service
                             issue [CVE-2026-15588]; fix integer underflow
                             issue [CVE-2026-58016]; fix out of bounds write
                             issue [CVE-2026-16118]

  glibc                      Fix buffer overflow/underflow issues
                             [CVE-2026-5928 CVE-2026-5450]; compatibility
                             with linux 7.0 headers

  gnupg2                     Rebuild with updated glibc

  goaccess                   Fix out of bounds write issue [CVE-2026-54715];
                             fix denial of service issue [CVE-2026-55768
                             CVE-2026-55777]

  gpsd                       Fix gpsprof command and code injection in
                             gnuplot script generation [CVE-2026-58459
                             CVE-2026-60122]

  gzip                       Fix insecure temporary file handling issue
                             [CVE-2026-41991]; fix buffer overflow issue
                             [CVE-2026-41992]

  imagemagick                Fix buffer overflow isses [CVE-2026-56362
                             CVE-2026-56372 CVE-2026-56374 CVE-2026-61464];
                             fix memory leak issues [CVE-2026-56366
                             CVE-2026-56375 CVE-2026-61863 CVE-2026-61864
                             CVE-2026-61865 CVE-2026-61866 CVE-2026-61867
                             CVE-2026-61868 CVE-2026-61869 CVE-2026-61870
                             CVE-2026-61871 CVE-2026-61872]; fix use-after-
                             free issues [CVE-2026-56373 CVE-2026-61857
                             CVE-2026-61860 CVE-2026-61861]; fix denial of
                             service issue [CVE-2026-61465]; fix policy
                             bypass issues [CVE-2026-61858 CVE-2026-61859];
                             fix information disclosure issue
                             [CVE-2026-61862]

  incus                      Fix path traversal issue [CVE-2026-81500]; fix
                             insufficent access check issue [CVE-2026-81501]

  integrit                   Rebuild with updated glibc

  libcap2                    Rebuild with updated glibc

  libdatetime-timezone-perl  Update to Olson 2026c; Alberta, CA permanently
                             -06; Morocco, permanently 00

  libdbd-csv-perl            Fix test failure

  libhttp-tiny-perl          Fix CRLF validation issue [CVE-2026-7010]; fix
                             credential forwarding on redirects issue
                             [CVE-2026-7017]

  libio-compress-perl        Fix header parsing issue [CVE-2025-15649]; fix
                             denial of service issue [CVE-2026-48959]; fix
                             crash in zipdetails [CVE-2026-48961]; fix code
                             execution issue [CVE-2026-48962]

  libmodule-cpants-analyse-  Backport fix for interoperability with
     perl                    Archive::Tar >= 3.08

  libmongocrypt              Fix missing input validation issue
                             [CVE-2026-81523]

  libnet-cidr-set-perl       Fix IPv4/IPv6 CIDR parsing validation
                             [CVE-2026-49940 CVE-2026-49941 CVE-2026-49942]

  libnfs                     Fix integer overflow [CVE-2026-53689]

  libraw                     Fix out of bounds read issue [CVE-2026-5342];
                             fix integer overflow issues [CVE-2026-20884
                             CVE-2026-24450]; fix buffer overflow issues
                             [CVE-2026-20889 CVE-2026-21413 CVE-2026-24660]

  libsdl2-image              Fix out of bounds read issue [CVE-2026-35444];
                             improve parser robustness

  libsdl3-image              Fix out of bounds read issue [CVE-2026-35444];
                             improve parser robustness

  libsocket-perl             Fix out of bounds read issue [CVE-2026-12087]

  libssh2                    Fix buffer overflow issues [CVE-2026-58050
                             CVE-2026-66035 CVE-2026-58051]; fix double free
                             issue [CVE-2026-66032]; fix integer underflow
                             issue [CVE-2026-66033]; fix data leak issue
                             [CVE-2026-66034]

  libvirt                    Fix buffer overflow issue [CVE-2026-18917]; fix
                             record injection issue [CVE-2026-61477]; fix
                             denial of service issue [CVE-2026-61478]; fix
                             privilege escalation issue [CVE-2026-63622];
                             fix information disclosure issue
                             [CVE-2026-63623]

  libwebsockets              Fix denial of service issue [CVE-2026-10650];
                             fix out of bounds write issue [CVE-2026-78161]

  llvm-toolchain-22          New package to support chromium builds

  lua-geoip                  Fix failure to build after geoip downgrade

  lwip                       Fix SNMPv3 authentication buffer overflow
                             [CVE-2026-8836]

  lxc                        Rebuild with updated glibc; fix memory leak
                             issue; fix running nested containers using
                             current versions of runc

  mariadb                    New upstream stable release; fix code execution
                             issues [CVE-2026-44168 CVE-2026-48163
                             CVE-2026-48165]; fix authorization bypass
                             [CVE-2026-44169]; fix path traversal issue
                             [CVE-2026-44171]; fix SQL injection issue
                             [CVE-2026-44172]; fix incomplete privilege
                             check issue [CVE-2026-44173]; fix "Illegal mix
                             of collations" error; fix "Mroonga hangs on
                             invalid index flag"; fix crash in
                             information_schema.table_constraints

  mbedtls                    Fix signature algorithm injection issue
                             [CVE-2026-25834]; fix PSA random generator
                             cloning issue [CVE-2026-25835]; fix improper
                             validation issue [CVE-2026-34872]; fix client
                             impersonation issue [CVE-2026-34873]; fix NULL
                             pointer dereference issue [CVE-2026-34874]; fix
                             buffer overflow issue [CVE-2026-34875]; fix
                             validation bypass issue [CVE-2026-34876]

  milib                      Handle uncaught exceptions

  mongo-c-driver             Fix missing input validation issue
                             [CVE-2026-81524]

  mrtg                       Fix privilege escalation issue [CVE-2026-72694]

  node-lodash                Fix prototype pollution issues [CVE-2025-13465
                             CVE-2025-13465]; validate imports keys in
                             _.template [CVE-2026-4800]

  onionshare                 Prevent writing files in Receive mode when file
                             uploads are disabled [CVE-2026-54707]; prevent
                             empty folder from being created when no file is
                             uploaded [CVE-2026-54706]

  opencryptoki               Fix privilege escalation issue
                             [CVE-2026-23893]; fix out of bounds read issue
                             [CVE-2026-40253]

  openssl                    New upstream release

  openvpn-dco-dkms           Fix use-after-free in peer teardown

  org-roam                   Add missing dependency on elpa-emacsql-sqlite

  patool                     Fix path traversal vulnerability
                             [CVE-2026-29509]

  pcre2                      Fix several out of bounds access issues

  perl                       Fix credential forwarding on redirects issue
                             [CVE-2026-7017]; fix symlink extraction issue
                             [CVE-2026-42496]; fix hardlink extraction issue
                             [CVE-2026-42497]; fix out of bounds read issues
                             [CVE-2026-12087 CVE-2026-57432]; fix incorrect
                             regular expression match issue
                             [CVE-2026-13221]; fix header parsing issue
                             [CVE-2025-15649]; fix CRLF validation issue
                             [CVE-2026-7010]; fix buffer overflow issue
                             [CVE-2026-8376]; fix denial of service issue
                             [CVE-2026-48959]; fix crash in zipdetails
                             [CVE-2026-48961]; fix code execution issue
                             [CVE-2026-48962]; fix signed integer overflow
                             issue [CVE-2026-57433]

  php-guzzlehttp-psr7        Fix CRLF injection in HTTP start-line parsing
                             [CVE-2026-55766]

  proftpd-dfsg               Fix SQL injection issue [CVE-2026-44331]; fix
                             buffer overflow issues [CVE-2026-53994
                             CVE-2026-63090]; fix integer overflow issue
                             [CVE-2026-63091]

  pyasn1                     Fix denial of service issues [CVE-2026-59884
                             CVE-2026-59885 CVE-2026-59886]

  python-ecdsa               Prevent exceptions when handling truncated DER
                             [CVE-2026-33936]

  python3.13                 Fix use-after-free in dict.clear() with
                             embedded values, resolving regression from
                             previous version; fix injection issue
                             [CVE-2026-0864]; fix file overwrite issue
                             [CVE-2026-11940]; fix denial of service issues
                             [CVE-2026-11972 CVE-2026-6879]; fix incorrect
                             handling of user / group IDs in tar files
                             [CVE-2026-4360]

  qemu                       New upstream stable release; fix integer
                             overflow issue [CVE-2026-15264]; fix secure boot
                             bypass [CVE-2026-16288]; fix infinite loop
                             [CVE-2026-16457]; fix buffer overflow issues
                             [CVE-2026-17516 CVE-2026-50626 CVE-2026-58581
                             CVE-2026-58582 CVE-2026-63110; virtio-gpu:
                             reject requests with short/truncated control
                             headers [CVE-2026-18054]; fix use-after-free
                             issues [CVE-2026-50624 CVE-2026-63322
                             CVE-2026-63323]; fix out of bounds write issue
                             [CVE-2026-61402]; hw/uefi: add post_load checks
                             [CVE-2026-61404]; fix denial of service issues
                             [CVE-2026-61405 CVE-2026-61406]; fix memory
                             leak issue [CVE-2026-61476]; fix out of bounds
                             read issues [CVE-2026-63109 CVE-2026-63320
                             CVE-2026-65928 CVE-2026-65929 CVE-2026-66021];
                             fix 9pfs Readonly O_TRUNC/O_APPEND Bypass issue
                             [CVE-2026-63318]; virtio: use masked features
                             with set_features_ex [CVE-2026-63321]; virtio-
                             net: qemu_bh_new_guarded uses wrong
                             DeviceState, bypassing MMIO reentrancy
                             protection [CVE-2026-66022]

  refpolicy                  Enable usbguard SELinux policy and fix its
                             confinement; fix SELinux policy for PAM login
                             records, chromium clipboard, pulseaudio,
                             systemd-nspawn/passwd-agent, dhcpc/ntp, and
                             sympa file labelling

  rsyslog                    Fix denial of service issue [CVE-2026-19654];
                             omfwd regression fix: avoid false active target
                             change log message; fix buffer overflow issues
                             [CVE-2026-78002 CVE-2026-61548]

  rust-cbindgen-web          New package to support browser builds

  rustc                      Fix documentation merging and fix build on
                             32-bit ARM platforms; fix tar header processing
                             and an unpack vulnerability [CVE-2026-33055
                             CVE-2026-33056]; fix cargo credential leakage
                             and cache poisoning [CVE-2026-5222
                             CVE-2026-5223]

  rustc-web                  New package to support browser builds

  samba                      New upstream stable release

  sash                       Rebuild with updated glibc

  sbsigntool                 Fix intermediate certificate verification

  sg3-utils                  Fix missing sg_inq output fields

  snapd                      Rebuild with updated glibc

  socat                      Fix buffer overflow issue [CVE-2026-56123]

  spip                       Security fixes

  sqlite3                    Fix FTS5 handling of corrupt records
                             [CVE-2026-11822 CVE-2026-11824]

  squid                      Fix out of bounds read issue [CVE-2026-33515]

  tini                       Rebuild with updated glibc

  transmission               Fix clickjacking issue [CVE-2026-38978]

  tripwire                   Rebuild with updated glibc

  tsocks                     Rebuild with updated glibc

  tzdata                     New upstream stable release; update timezone
                             data for Alberta and Morocco; update leap
                             second data

  u-boot                     Fix BOOTP/DHCP buffer overread
                             [CVE-2024-42040]; fix FIT signature
                             verification bypass [CVE-2026-46728]

  unixodbc                   Fix memory leaks on dlclose()

  user-mode-linux            Rebuild with updated linux

  wolfssl                    Fix digest, MAC, and AES-GCM validation
                             [CVE-2026-5194 CVE-2026-6329 CVE-2026-6331
                             CVE-2026-55967]; fix PKCS7 bounds, overflow,
                             and certificate handling [CVE-2026-6094
                             CVE-2026-6678 CVE-2026-6681 CVE-2026-7511];
                             ensure certificate validation [CVE-2026-55960
                             CVE-2026-55961 CVE-2026-6450 CVE-2026-6731];
                             fix TLS handshake state and algorithms
                             [CVE-2026-55962 CVE-2026-6092 CVE-2026-6325]

  xapian-core                Fix missing escaping

  xfsprogs                   Avoid unnecessary "permission denied" logging
                             in other services

  zsh                        Rebuild with updated glibc


A complete list of all accepted and rejected packages together with
rationale is on the preparation page for this revision:

  <https://release.debian.org/proposed-updates/stable.html>


If you encounter any issues, please don't hesitate to get in touch with the
Debian Release Team at "[email protected]".

Attachment: signature.asc
Description: This is a digitally signed message part

Reply via email to