Debian 13.4 has been released.

The Debian Project is pleased to announce the fourth update of its stable distribution Debian 13 (code name trixie), which includes important updates in security and stability of key components.

Release 13.4 is not a new version of the distribution but a set of package updates that accumulate critical bug fixes and vulnerabilities, many of which had previously been released as separate security announcements.

This update focuses primarily on enhancing the reliability of network services and critical system components, as well as addressing a number of vulnerabilities.

Key fixes

  • Apache2: A regression related to the HTTP/2 protocol has been fixed.
  • bird2: Fixed an issue with flags for deprecated prefixes in RAdv (Router Advertisements for IPv6) and resolved a crash when exporting routes with non-BGP attributes in the BMP protocol.
  • ifupdown: Improved handling of DAD (Duplicate Address Detection) for IPv6, as well as the invocation order for the dhclient.
  • open-iscsi: Fixed an issue with the detection of static iSCSI nodes.
  • chrony: The time synchronization daemon has been adapted for compatibility with new kernels.
  • clatd (CLAT for IPv6): Fixed the installation of systemd units and the path for the NetworkManager dispatcher.

Security fixes

  • openssh: Potential issues with process tracking in MaxStartups have been resolved, as well as vulnerabilities that could lead to code execution (CVE-2025-61984, CVE-2025-61985).
  • glibc (GNU C library): Update from the stable upstream branch, fixing several critical issues: heap corruption (CVE-2026-0861), stack content leakage (CVE-2026-0915), and the use of uninitialized memory (CVE-2025-15281).
  • mariadb: New stable release addressing the potential for arbitrary code execution (CVE-2025-13699) and a denial of service issue (CVE-2026-21968).
  • postgresql-17: New stable release including a fix for buffer overflow (CVE-2026-2006).
  • wget2: Fixed vulnerabilities that allowed files to be overwritten via metalink (CVE-2025-69194) and triggered remote buffer overflow (CVE-2025-69195).
  • erlang: Resolved issues leading to excessive resource consumption (CVE-2025-48038, among others) and traffic redirection.
  • dpkg: Fixed a vulnerability leading to denial of service (CVE-2026-2219).
  • Wireshark: A new stable release that fixes memory exhaustion issues in the USB HID dissector (CVE-2026-3201) and crashes in the RF4CE Profile dissector (CVE-2026-3203).
  • Xen: The hypervisor has been updated to a new stable release that addresses a buffer overflow (CVE-2025-58150) and incomplete isolation of vCPUs (CVE-2026-23553).

System component updates

  • GRUB2: Fixed a problem with identifying the root ZFS filesystem across multiple architectures (amd64, arm64, ia32).
  • Sudo: Fixed a regression related to filenames in sudoers.d that contain colons.
  • Systemd-resolved: Fixed a bug in the debvm script regarding the installation of systemd-resolved.

Source: linux.org.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster