Views
158

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

AI enhanced content

Update Summary

Debian 13 (trixie) release notes cover the upgrade from bookworm, new architecture support, and major platform changes such as 64-bit time_t, OpenSSH DSA removal, and /tmp moving to tmpfs. They also list important upgrade cautions, deprecations, and known severe bugs.

Update Details

Security

  • arm64 hardening against ROP and COP/JOP attacks using PAC and BTI when supported by hardware
  • OpenSSH no longer supports DSA keys; DSA is considered weak and should be replaced with stronger key types
  • openssh-server no longer reads ~/.pam_environment by default because of its security history
  • Removed git-daemon-run and git-daemon-sysvinit packages due to security reasons
  • Debian notes limited security support for some browser engines, especially qtwebengine-based applications

Bug Fixes

  • Improved package versions across the distribution, including major updates to core components such as Apache, Bash, OpenSSL, systemd, and the Linux kernel
  • apt full-upgrade may fail with 'Could not perform immediate configuration'; retrying with APT::Immediate-Configure=0 is documented as a workaround
  • dpkg warnings about being unable to delete old directories during usrmerge finalization can be safely ignored
  • Network interface names may change after upgrade on some systems, especially with the i40e driver or _SUN ACPI exposure
  • RabbitMQ cannot be directly upgraded from bookworm; the database may need to be wiped and recreated after upgrade
  • MariaDB major version upgrades require a clean shutdown before upgrading to avoid startup failure
  • OpenLDAP TLS support now comes from OpenSSL instead of GnuTLS, changing available options and behavior
  • Samba AD DC functionality and VFS modules were reorganized into separate packages
  • libvirt packaging was overhauled into more granular binary packages

New Features

  • Official support for riscv64
  • HTTP Boot support for Debian Installer and Debian Live Images on supported firmware
  • Spell-checking support in Qt WebEngine browsers using Hunspell BDIC dictionaries
  • curl and libcurl now support HTTP/3, and curl ships wcurl as a wget-like download helper
  • 64-bit time_t ABI transition on all architectures except i386
  • Debian now ships debian-repro-status and rebuilderd for reproducible build tracking
  • Plasma 6, KDE Frameworks 6, and updated KDE Gear applications
  • Cloud images for AWS, Azure, OpenStack, and plain VM deployments

Known Issues

  • Interrupted remote upgrades over SSH can leave bookworm systems inaccessible until OpenSSH is updated first
  • i386 is no longer supported as a regular architecture and should not be upgraded to trixie
  • armel is the last release supported in trixie and has limited hardware support
  • mipsel and mips64el architectures have been removed
  • A too-small /boot partition can cause the upgrade to fail; Debian recommends at least 768 MB and about 300 MB free
  • On upgraded systems, /tmp becomes tmpfs after reboot, which can hide existing files in /tmp
  • /etc/sysctl.conf is no longer honored by systemd-sysctl
  • Ping no longer runs with elevated privileges and depends on net.ipv4.ping_group_range behavior
  • Some systems may lose network connectivity after reboot due to interface name changes
  • Dovecot configuration is incompatible with previous versions and should be ported before production upgrade
  • strongSwan is migrating to charon-systemd; existing charon-daemon setups need migration planning
  • Bacula database schema upgrade can take a very long time and requires substantial extra disk space
  • Known severe bugs include issues in apt, linux, grub-efi-amd64, kmod, python3.13, and others

Hints

  • Upgrade path is supported only from Debian 12 (bookworm) and only from the latest point release
  • APT sources should be migrated to deb822 .sources files; apt modernize-sources is mentioned as a helper
  • For remote upgrades, use screen or tmux and ensure recovery access such as a serial console
  • Back up /etc, /var/lib/dpkg, /var/lib/apt/extended_states, and package selections before upgrading
  • Install a linux-image-* metapackage after upgrade so future kernel updates are pulled in automatically
  • If using encrypted filesystems, ensure systemd-cryptsetup is installed before rebooting
  • Plain-mode dm-crypt devices may need explicit cipher, size, and hash settings in /etc/crypttab
  • APT sources should point to trixie, trixie-updates, and trixie-security; bookworm entries should be removed after upgrade
  • The new default /tmp tmpfs size can be adjusted with systemctl edit tmp.mount or disabled by masking tmp.mount
  • apt autoremove is recommended after the upgrade to clean up automatically installed packages
  • The old .gpg keyring paths are now compatibility symlinks to .pgp canonical paths and will eventually be removed

Links

Product Information

Vendor: Debian

Product: Server

Product type: Software

Application category: Utilities

Platform: Linux

Variant: 13 Trixie

Version: Debian 13 (trixie)

Vendor release date: Jul 11, 2026

Original release notes: View on vendor site

Published on updatealert.io: Aug 1, 2026