Debian published kernel security advisory DSA-6528-1 on September 29 for its stable Trixie release. The Debian kernel security update addresses multiple flaws that could lead to privilege escalation, denial of service or information leaks. Administrators should check their installed kernel packages and plan a reboot after upgrading, since installing a kernel package alone does not put the new kernel into use.
What Debian’s advisory confirms
Debian identifies the affected source package as linux. For Debian 13 “Trixie,” the project says the issues are fixed in version 6.12.111-1. The security tracker entry for DSA-6528-1 provides the advisory and links to individual CVE records.
The notice lists many CVE identifiers. That does not mean every machine has the same exposure. Risk depends on the hardware, enabled kernel features and workloads. It is better to follow Debian’s package guidance than to choose one alarming CVE from a long list and assume it describes every installation.
Check the running kernel and available update
On a Trixie system, run uname -r to see the kernel currently running. Then refresh package metadata with sudo apt update and inspect pending upgrades with apt list --upgradable. The package names can differ by architecture and installed kernel flavour. Look for the relevant linux-image metapackage and the new signed kernel image package.
Install, then restart at a planned time
Use your normal Debian update process, such as sudo apt upgrade, to install the security packages. If your environment uses a controlled maintenance window, schedule it promptly. After the packages install, reboot and run uname -r again. Confirm that the system started the updated kernel, then check services and hardware that matter to your workload.
Our previous coverage of upstream stable kernel updates explains why a new version number alone does not describe a distribution’s patch status. Debian tests and ships its own packaged builds; follow the Debian advisory for a Debian host.
Keep the scope clear
DSA-6528-1 is a Trixie stable advisory. Do not copy its package version into instructions for another Debian release, Ubuntu or a different distribution. Their maintainers may backport fixes under different version numbers and schedules. On managed fleets, check the installed package and the running kernel separately before closing the change ticket.
Debian’s security page and tracker carry the official status. The project recommends upgrading the linux packages; a successful reboot is the practical final check that the updated kernel is active.
