Debian has released Debian 13.6 as a point update focused on security and maintenance, alongside Debian 12.15 for the previous stable branch. Debian 13.6 bundles roughly 120 security updates and more than 120 bug fixes, with patches affecting the Linux kernel and widely deployed packages including Nginx, Redis, FFmpeg, Thunderbird, Chromium, PHP, Postfix, Samba, wireless-regdb, and Wireshark. The update is intended to bring existing installations current rather than introduce a new major version.
A notable change in Debian 13.6 is an updated shim-signed and fwupd 2.0.20 stack to support newer Microsoft UEFI Secure Boot certificate chains and updates to Secure Boot CA, KEK, and DBX databases after expiration issues with the default UEFI Secure Boot CA used on many PCs. Debian also reverted or removed the legacy geoip-database package because newer GeoLite data was found incompatible with Debian Free Software Guidelines and the older dataset had become outdated, pushing migration toward maintained alternatives such as GeoLite2.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Debian announced on July 11, 2026 that Debian 12.15 is the fifteenth and final point release of Debian 12 "bookworm" oldstable. The announcement also said standard Debian Release Team, Security Team, and Backports support for Debian 12 had ended, with limited ongoing support moving to Debian LTS for some architectures.
Debian 13.6 includes shim-signed and fwupd 2.0.20 updates to support newer Microsoft UEFI Secure Boot certificate infrastructure and updating Secure Boot CA, KEK, and DBX databases. The change addresses the expiration of the default UEFI Secure Boot CA used on most PCs.
The Debian 13.6 release reverted the geoip-database package to a December 2019 state because newer GeoLite versions were found incompatible with the Debian Free Software Guidelines. Other reporting describes the package as outdated and being removed or replaced due to licensing and maintenance issues.
Debian 13.6 was released as a new point release for Debian Trixie, bundling the latest security fixes and maintenance updates. The release includes numerous package updates and security advisories affecting components such as the Linux kernel, Nginx, Redis, FFmpeg, Thunderbird, Chromium, and PHP.
Reporting on the Debian 13.6 release also states that Debian 12.15 was released in parallel as an updated point release focused on security fixes and important bug corrections. The Debian 12 release is described as continuing under LTS-related support arrangements.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
10 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcehelpnetsecurity.com
Open sourcedebian.org
Open sourcedebian.org
Open sourcedeb.freexian.com
Open sourcedev.maxmind.com
Open sourceopennet.ru
Open sourceopennet.me
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.