Views
22

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

AI enhanced content

Update Summary

Debian 11 (bullseye) release notes for arm64 cover major distribution changes, upgrade guidance from Debian 10, and known issues. Highlights include cgroup v2 by default, persistent systemd journal, exFAT kernel support, and security-related defaults like yescrypt password hashing.

Update Details

Security

  • Password hashing now uses yescrypt by default instead of SHA-512, improving resistance to dictionary attacks.
  • Linux enables user namespaces by default to improve sandboxing for browsers and container tools.
  • Linux disables unprivileged bpf() calls by default for security hardening.
  • Security archive layout changed to bullseye-security, which may require APT source and pinning updates.

Bug Fixes

  • OpenSSH upgrade may temporarily block new SSH connections during the upgrade; upgrading openssh-server first is recommended.
  • Open vSwitch may require changing /etc/network/interfaces from allow-ovs to auto to recover bridges after boot.
  • libgc1c2-dependent packages may need two upgrade runs to complete successfully.
  • rsync --noatime was renamed to --open-noatime; older scripts may need updates.
  • fuse3 replaces fuse for packages such as gvfs-fuse, kio-fuse, and sshfs.

New Features

  • CUPS gains ipp-usb support for driverless USB printing.
  • SANE driverless scanning is supported via sane-escl and sane-airscan.
  • Systemd defaults to cgroup v2 and enables persistent journal storage by default.
  • Debian 11 includes the Bazel build system via bazel-bootstrap.
  • Kernel support for exFAT is included and used by default for mounting exFAT filesystems.

Known Issues

  • XFS no longer supports the barrier and nobarrier mount options.
  • The rescue boot option is unusable without a root password unless SYSTEMD_SULOGIN_FORCE=1 or init=/sbin/sulogin --force is used.
  • 32-bit Xen PV guests are not supported.
  • Some Intel microcode updates may break Wi-Fi on certain CoffeeLake systems or cause boot hangs on some Skylake systems.
  • fail2ban may not send email correctly when using mail from bsd-mailx.

Hints

  • Upgrade from Debian 10 (buster) only; direct upgrades from older releases are not supported.
  • Before upgrading, back up /etc, /var/lib/dpkg, /var/lib/apt/extended_states, and package selections.
  • Use apt upgrade --without-new-pkgs for a minimal upgrade, then apt full-upgrade.
  • Record the upgrade session with script to aid troubleshooting.
  • Update APT sources from buster/updates to bullseye-security and remove proposed-updates before upgrading.
  • Install a linux-image-* metapackage after upgrading to ensure future kernel updates are pulled in.
  • For OpenStack nodes, cgroup v1 may need to be re-enabled with kernel parameters.
  • For Exim 4.94, existing configurations may need changes because tainted data handling is stricter.

Links

Product Information

Vendor: Debian

Product: Server

Product type: Software

Application category: Utilities

Platform: Linux

Variant: 11 Bullseye

Vendor release date: Aug 31, 2024

Original release notes: View on vendor site

Published on updatealert.io: Jul 31, 2026