CVE Tools

Debian 13.7 ships the fixes behind 92 security advisories, updates 106 packages

Help Net SecurityBy Sinisa Markovic

RoundupDebian Trixielinux source package

Our summary

The Debian project has released version 13.7, codenamed "trixie," which incorporates 92 previously published security advisories and corrections for 106 source packages. This point release addresses significant vulnerabilities in key components such as QEMU, which includes 25 fixed issues including a secure boot bypass (CVE-2026-16288), and ImageMagick, with 24 fixes. Other notable updates include patches for glibc buffer overflows (CVE-2026-5928, CVE-2026-5450) and u-boot FIT image verification flaws (CVE-2026-46728).

Existing systems should update their package managers to fetch these security improvements, while new installations from the updated media will include these fixes by default.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store