Views
23

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

AI enhanced content

Update Summary

Debian 11 (bullseye) release notes for IBM System z (s390x) describe the upgrade from buster, major package and desktop updates, and important migration changes such as cgroup v2, persistent journaling, and yescrypt password hashing.

Update Details

Security

  • Local account password hashing changes from SHA-512 to yescrypt by default for improved resistance to password guessing attacks.
  • Unprivileged bpf() calls are disabled by default in Linux 5.10 for hardening.
  • User namespaces are enabled by default to improve sandboxing for browsers and container tools.
  • Security support is limited for some browser engines and Go-based packages; they should not be used against untrusted websites where unsupported.

Bug Fixes

  • OpenSSH upgrade can block new SSH connections for longer than usual; upgrade openssh-server first if upgrading remotely.
  • Open vSwitch may fail to recover bridges after boot unless /etc/network/interfaces is adjusted from allow-ovs to auto.
  • Exim 4.94 introduces tainted-data handling and may require configuration updates or a temporary compatibility setting.
  • rdiff-backup server and client must be upgraded in lockstep because version 1 and 2 protocols are incompatible.
  • Upgrades involving libgc1c2 may require running the upgrade twice.
  • fuse3 replaces fuse for packages such as gvfs-fuse, kio-fuse, and sshfs.
  • The XFS barrier and nobarrier mount options are no longer supported and must be removed from /etc/fstab.
  • The security archive layout changed from buster/updates to bullseye-security.

New Features

  • Driverless printing is extended with ipp-usb for USB-connected printers.
  • Driverless scanning support is available through sane-escl and sane-airscan.
  • A new generic open command is provided as an alias to xdg-open or run-mailcap.
  • Systemd defaults to cgroup v2 and enables persistent journal storage by default.
  • Fcitx 5 is introduced as the successor to Fcitx 4.
  • Kernel support for exFAT is included and used by default for mounting exFAT filesystems.
  • Bazel is initially available via bazel-bootstrap.

Known Issues

  • The rescue boot option is unusable without a root password unless SYSTEMD_SULOGIN_FORCE=1 or init=/sbin/sulogin --force is used.
  • 32-bit Xen PV guests are no longer supported and must be converted to 64-bit PC architecture.
  • Intel microcode updates may break some CoffeeLake Wi-Fi setups or cause boot hangs on some Skylake systems with outdated firmware/BIOS.
  • sendmail is stopped during the upgrade, causing more downtime than usual.
  • fail2ban may not send mail correctly when using mail from bsd-mailx.
  • Known severe bugs remain in packages including ca-certificates-java, cron, mariadb-server-10.5, openssh-server, and others listed in the release notes.

Hints

  • Before upgrading, back up /etc, /var/lib/dpkg, /var/lib/apt/extended_states, and package selections.
  • Use apt upgrade --without-new-pkgs for a minimal upgrade, then apt full-upgrade.
  • Record the upgrade session with script so you can review or report issues later.
  • Update APT sources from buster to bullseye and change security entries to bullseye-security.
  • Install a linux-image-* metapackage after upgrading so future kernel updates are pulled in automatically.
  • For remote upgrades, use screen and ensure a recovery path such as serial console access.
  • If you rely on NIS/NIS+, verify that libnss-nis and libnss-nisplus are installed after the upgrade.
  • If you need password-hash compatibility with Debian 10, change yescrypt to sha512 in /etc/pam.d/common-password.

Links

Product Information

Vendor: Debian

Product: Server

Product type: Software

Application category: Utilities

Platform: Linux

Variant: 11 Bullseye

Vendor release date: Aug 31, 2024

Original release notes: View on vendor site

Published on updatealert.io: Jul 31, 2026