Debian Server 11 Bullseye Update
Your rating
Rate update installation process
Risk factor
No ratings yet. Be the first to rate this update.
AI enhanced content
Update Summary
Debian 11 (bullseye) release notes for arm64 cover major distribution changes, upgrade guidance from Debian 10, and known issues. Highlights include cgroup v2 by default, persistent systemd journal, exFAT kernel support, and security-related defaults like yescrypt password hashing.
Update Details
Security
- Password hashing now uses yescrypt by default instead of SHA-512, improving resistance to dictionary attacks.
- Linux enables user namespaces by default to improve sandboxing for browsers and container tools.
- Linux disables unprivileged
bpf()calls by default for security hardening. - Security archive layout changed to
bullseye-security, which may require APT source and pinning updates.
Bug Fixes
- OpenSSH upgrade may temporarily block new SSH connections during the upgrade; upgrading
openssh-serverfirst is recommended. - Open vSwitch may require changing
/etc/network/interfacesfromallow-ovstoautoto recover bridges after boot. libgc1c2-dependent packages may need two upgrade runs to complete successfully.rsync --noatimewas renamed to--open-noatime; older scripts may need updates.fuse3replacesfusefor packages such asgvfs-fuse,kio-fuse, andsshfs.
New Features
- CUPS gains
ipp-usbsupport for driverless USB printing. - SANE driverless scanning is supported via
sane-esclandsane-airscan. - Systemd defaults to cgroup v2 and enables persistent journal storage by default.
- Debian 11 includes the Bazel build system via
bazel-bootstrap. - Kernel support for exFAT is included and used by default for mounting exFAT filesystems.
Known Issues
- XFS no longer supports the
barrierandnobarriermount options. - The rescue boot option is unusable without a root password unless
SYSTEMD_SULOGIN_FORCE=1orinit=/sbin/sulogin --forceis used. - 32-bit Xen PV guests are not supported.
- Some Intel microcode updates may break Wi-Fi on certain CoffeeLake systems or cause boot hangs on some Skylake systems.
fail2banmay not send email correctly when usingmailfrombsd-mailx.
Hints
- Upgrade from Debian 10 (buster) only; direct upgrades from older releases are not supported.
- Before upgrading, back up
/etc,/var/lib/dpkg,/var/lib/apt/extended_states, and package selections. - Use
apt upgrade --without-new-pkgsfor a minimal upgrade, thenapt full-upgrade. - Record the upgrade session with
scriptto aid troubleshooting. - Update APT sources from
buster/updatestobullseye-securityand removeproposed-updatesbefore upgrading. - Install a
linux-image-*metapackage after upgrading to ensure future kernel updates are pulled in. - For OpenStack nodes, cgroup v1 may need to be re-enabled with kernel parameters.
- For Exim 4.94, existing configurations may need changes because tainted data handling is stricter.
Links
-
Debian Bullseye release notes
https://www.debian.org/releases/bullseye/releasenotes
-
Debian Bullseye installer images and guide
https://www.debian.org/releases/bullseye/debian-installer/
Product Information
Vendor: Debian
Product: Server
Product type: Software
Application category: Utilities
Platform: Linux
Variant: 11 Bullseye
Vendor release date: Aug 31, 2024
Original release notes: View on vendor site
Published on updatealert.io: Jul 31, 2026