Debian 13.6 and 12.15 Released: Security Updates and Secure Boot CA Transition
Debian 13.6 has been released as the sixth point release of Debian 13 (Trixie). It primarily includes security updates and bug fixes for existing installations. In total, the release contains 124 bug fixes and 120 security updates covering 109 Debian Security Advisories (DSAs).
At the same time, Debian 12.15 has been released as the fifteenth and final point release for Bookworm. This marks the end of regular support from the Release Team, Security Team, and Backports Team. Selected architectures will continue receiving updates through Debian's Long Term Support (LTS) program, but users are encouraged to upgrade to Debian 13.
Secure Boot CA expires
The 2013 UEFI Secure Boot Certificate Authority (CA), which is present on most systems, has expired. Future updates to shim-signed may prevent systems with Secure Boot enabled from booting if the required certificate updates are not installed.
Debian 13.6 ships with fwupd 2.0.20, which can update the Secure Boot CA, the Key Exchange Key (KEK), and the revocation database (DBX). Debian recommends installing the updates provided by your system OEM, as described on the SecureBoot/CAChanges page in the Debian Wiki.
geoip-database reverted
For licensing reasons, geoip-database has been reverted to a version from approximately December 2019. Newer GeoLite releases are not compatible with the Debian Free Software Guidelines (DFSG). Users who require up-to-date GeoIP data should obtain a GeoLite license directly.
Security updates
Debian 13.6 fixes vulnerabilities in a wide range of packages, including:
- Chromium
- Linux kernel
- Firefox ESR
- Thunderbird
- PHP 8.4
- Apache HTTP Server
- curl
- calibre
- dhcpcd
Altogether, the release includes fixes covered by 109 Debian Security Advisories (DSAs), along with numerous additional bug fixes.
Installer
The debian-installer now uses Linux ABI 6.12.94+deb13.
Updating
Existing installations can be updated as usual:
sudo apt update && sudo apt upgrade
Users installing from existing ISO images only need to point their package sources to a current Debian mirror. Older Trixie and Bookworm installation media remain usable, with packages being updated after installation.
Conclusion
This is a routine point release focused on stability and security. The most significant change is the Secure Boot certificate transition. Systems using Secure Boot should apply the recommended certificate updates to avoid boot issues with future shim-signed updates. The remaining changes consist primarily of security updates and bug fixes across the Debian package archive.
Release notes: Debian 13.6 | Debian 12.15