Vulnerabilities · 120 days ago
The real risk is stale install media, not a surprise gap on hosts already tracking Debian security updates. Debian 13.5 mostly resets the baseline for new installs and golden images, so systems built from old media can boot into a vulnerable state and need immediate remediation.
The point release bundles roughly 100 security advisories and updates more than 130 source packages, including the kernel, Apache, OpenSSH, sudo, systemd, OpenSSL, glibc, and FreeRDP. Debian says fresh installer images will carry the same fixes, and existing trixie systems pulling from security.debian.org are already carrying most of these patches.
For offline and partially disconnected fleets, the release matters because the vulnerable baseline can persist in image pipelines long after the point release lands. The operational gap is in provisioning, not in the current stable branch itself.
CVEs in this update
10 CVEs
Across Secure Connect Gateway, OpenSSH, AIX, and related packages.
0 critical · 4 high · 3 medium · 3 low
0 in CISA KEV · 0 with EPSS above 1%
Highest severity: CVE-2026-23918 · 8.8 HIGH
Highest EPSS: CVE-2026-35385 · 0.56%
1 source covering this story
Debian 13.5 point release lands with security fixes, bug patches - Help Net Security
Debian 13.5 point release lands for trixie with security fixes, package updates, and an installer refresh from the Debian project.
Part of the PlainSec briefing for 2026-05-18