Article may be outdated

This article is 86 days old. Some details may have changed since publication.

Help Net Security·4 min read·hard

Debian 13.6 security update patches over a hundred advisories in trixie

A
Anamarija Pogorelec
Debian 13.6 security update patches over a hundred advisories in trixie
✦AI Summary

Debian 13.6 has been released to address over a hundred security advisories, including critical fixes for UEFI Secure Boot certificate expiration. The update also includes patches for the curl library and adjustments to geo-database licensing.

Why it matters

System administrators and Linux users must apply these updates to maintain system security and prevent boot failures caused by expired certificates.

✦Dive DeeperCreate a free account to unlock

Debian 13.6 security update patches over a hundred advisories in trixie Most PCs still run with a UEFI Secure Boot certificate authority, installed by default since 2013, that has now expired. That certificate signed the bootloaders letting machines start with Secure Boot turned on. Its expiry sits at the center of the sixth update to Debian 13, codenamed “trixie.” The point release carries mostly security corrections along with a few fixes for serious problems.

The Secure Boot problem gets handled through fwupd, updated to upstream version 2.0.20. The new build can update the Secure Boot certificate authority, the Key Exchange Key, and the revocation database on affected machines. Systems that skip these updates risk a specific failure. Future updates to “shim-signed” could leave them unable to boot with Secure Boot enabled. Debian advises users to apply the CA, KEK, and DBX updates supplied by their system OEM.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologyscience
✦

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in