A stable distribution is valued primarily for predictability, and Debian 13.6 strengthens it with a large set of fixes for Linux kernels, server software and virtualization tools. The Debian project released the sixth interim update of the Debian 13 trickee on July 11, 2026. No surprises, however, also did not do.
Debian 13.6 is not considered a new version of the operating system. The release brings together previously published security updates, corrects critical errors and offers fresh installation images. Already operating systems can be updated through the standard APT package manager.
One of the main changes is related to UEFI Secure Boot. The fwupd package was updated to version 2.0.20, which allows you to install new certificates and lists of prohibited signatures through the firmware. The certificate, which manufacturers have massively added to computers since 2013, has already expired. Without firmware updates, future downloaders with a new signature may not be launched on devices with a safe download.
The release also includes patches of Apache HTTP Server vulnerabilities, including memory errors, reading arbitrary files, cross-site scripting, and service failure. Curl no longer has to disclose accounts, tokens, and outdated cookies when redirected and some network connections. QEMU has been updated to a new stable version with fixes important for virtual machines.
The security updates received the kernel of Linux, OpenSSL, Chromium, Firefox ESR, Ngin, Redis, PostgreSQL 17, Thunderbird, Wireshark, Python 3.13 and other packages. At the same time, Debian returned the GeoIP base to a state of around December 2019, since new versions of GeoLite cannot be distributed according to the rules of the project. Current geolocation data will have to be obtained directly by GeoLite licenses.
Administrators are advised to upgrade the system to Debian 13.6 with apt update and apt upgrade commands. On computers with Secure Boot, you should also install in advance CA, KEK and DBX updates from the hardware manufacturer to avoid download problems after the change of certificates.
Debian 13.6 is not considered a new version of the operating system. The release brings together previously published security updates, corrects critical errors and offers fresh installation images. Already operating systems can be updated through the standard APT package manager.
One of the main changes is related to UEFI Secure Boot. The fwupd package was updated to version 2.0.20, which allows you to install new certificates and lists of prohibited signatures through the firmware. The certificate, which manufacturers have massively added to computers since 2013, has already expired. Without firmware updates, future downloaders with a new signature may not be launched on devices with a safe download.
The release also includes patches of Apache HTTP Server vulnerabilities, including memory errors, reading arbitrary files, cross-site scripting, and service failure. Curl no longer has to disclose accounts, tokens, and outdated cookies when redirected and some network connections. QEMU has been updated to a new stable version with fixes important for virtual machines.
The security updates received the kernel of Linux, OpenSSL, Chromium, Firefox ESR, Ngin, Redis, PostgreSQL 17, Thunderbird, Wireshark, Python 3.13 and other packages. At the same time, Debian returned the GeoIP base to a state of around December 2019, since new versions of GeoLite cannot be distributed according to the rules of the project. Current geolocation data will have to be obtained directly by GeoLite licenses.
Administrators are advised to upgrade the system to Debian 13.6 with apt update and apt upgrade commands. On computers with Secure Boot, you should also install in advance CA, KEK and DBX updates from the hardware manufacturer to avoid download problems after the change of certificates.