Debian 13.4 (codename Trixie) point release is now available, incorporating updates to numerous packages. Key highlights include a glibc update fixing heap corruption (CVE-2026-0861), stack leak (CVE-2026-0915), and uninitialized memory use (CVE-2025-15281); openssh fixes for possible code execution (CVE-2025-61984, CVE-2025-61985); MariaDB and PostgreSQL 17 upstream stable releases with security fixes; dpkg denial of service fix (CVE-2026-2219); suricata denial/overflow fixes; and dozens of other CVE patches across packages including apache2, erlang, glibc, libpng1.6, qemu, samba, sqlite3, wget2, wireshark, xen, and zabbix. Many packages were also rebuilt against the updated glibc.
Table of contents
Miscellaneous BugfixesSecurity UpdatesDebian InstallerURLsAbout DebianContact InformationSort: