The sixth corrective update for Debian 13 has been released, incorporating accumulated package updates and adding fixes to the installer. This release includes 124 updates addressing stability issues and 120 updates that fix vulnerabilities.
Notable changes in Debian 13.6 include an update to the shim-signed layer used for verified boot in UEFI Secure Boot mode. The layer has been updated due to the expiration of Microsoft’s certificate used for signing the bootloader. The new package version is signed with a certificate from Microsoft UEFI CA issued in 2023.
Additionally, the fwupd firmware update tooling has been updated to version 2.0.20. The new version features the ability to update the database of certificate authorities that issue certificates for Secure Boot, as well as the trusted key exchange key (KEK) database and the list of revoked keys (DBX). Users are advised to update these databases using the firmware update from their hardware manufacturer.
Due to licensing issues, the ‘geoip-database’ package, which contains the GeoLite database for geolocation purposes, IP addresseshas been replaced with an outdated version that was generated in December 2019, which may lead to outdated geolocation results in applications. A newer version of the database cannot be included in the distribution due to incompatibilities with the licensing requirements applicable in Debian. To obtain current data, it is recommended to download the GeoLite database directly. Other changes include updates to the latest stable versions of the postfix, samba, wireless-regdb, and wireshark packages.
Installation builds for Debian 13.6 will be prepared in the coming hours for fresh installations. Systems previously installed and kept up-to-date receive the updates present in Debian 13.6 through the standard update installation system. Security fixes included in new Debian releases are available to users as updates are released via security.debian.org.
A new release of the previous stable branch Debian 12.15 is now available, which includes 88 updates addressing stability issues and 97 updates resolving vulnerabilities. This is the last scheduled update for the Debian 12 branch, which has completed its main three-year support cycle provided by the Debian Release Team, Debian Security Team, and Debian Backports.
Going forward, vulnerability updates for Debian 11 will be released as part of the Extended Support (LTS) program, which will last until June 30, 2028. The scheduled support for the current Debian 13 branch will continue until August 9, 2028, after which LTS updates will be provided for this branch until June 30, 2030.
Updates for the LTS branch are managed by a separate group of developers, the LTS Team, formed from enthusiasts and representatives of companies interested in long-term update delivery for Debian. The LTS Team has taken over from the Debian Security Team and continued support for Debian 12 without interruption. Updates will be released for the i386, amd64, armhf, arm64, and ppc64el architectures.
The extended support period will not apply to certain packages, such as web applications for which it is impractical to maintain support for five years (it is recommended to use backports for continued use of such packages). Unsupported packages include chromium, xen, tor, phppgadmin, salt, snort, and libreswan, as well as all packages in the ‘games’ section. You can check for unsupported packages in your system using the check-support-status utility included in the debian-security-support package.
After the end of LTS support for Debian 12, an Extended LTS program will be available, through which the company Freexian aims to release vulnerability updates for a limited set of packages for the amd64, armel, and i386 architectures until 2033. Updates for the Extended LTS branches will be distributed through an external repository supported by Freexian. Access is free for everyone, and the range of supported packages depends on the total number of sponsors and their interests.
Source: opennet.ru
