Patching
Debian's 1,313-CVE kernel update: what to do with it
DSA-6528-1 brings Debian 13 to kernel 6.12.111-1 with 1,313 CVE fixes. How to install it, prove the new kernel is running, and spot hosts still exposed to exploited bugs.
On September 29, Debian published DSA-6528-1, a Linux kernel update for Debian 13 "Trixie" that lists 1,313 CVE IDs. The fixed package is linux 6.12.111-1. Debian's security tracker marks 6.12.107-1, the kernel in the main Trixie archive, as vulnerable. 9to5Linux called it probably the biggest kernel security release ever. Every Trixie machine running a Debian kernel is in scope: servers, cloud images (the -cloud-amd64 flavour), realtime builds and desktops.
The count is not a measure of danger. The advisory itself says the flaws "may lead to a privilege escalation, denial of service or information leaks" and reports no active exploitation. Most entries are low severity or depend on hardware, drivers or settings a given machine does not have. The real risk on a Debian estate sits somewhere else: the Linux kernel bugs CISA has listed as exploited were fixed in Trixie weeks or months ago, and any host that installed those kernels but never rebooted is still running the vulnerable one.
Why one advisory carries 1,313 CVEs
Two things stack up. Under the kernel project's current CVE policy, almost every commit that fixes a possible security problem gets a CVE, including ones with no known exploit path. Debian also does not ship each upstream stable release as its own advisory. It collects fixes from several upstream releases and ships them together, so a longer gap means a bigger batch. In this one, 1,295 of the IDs are from 2026, 15 from 2025 and 3 from 2024.
For triage, that means reading 1,313 descriptions is not a useful exercise. Treat DSA-6528-1 as a routine kernel roll-up: install it on the normal schedule, and spend the effort on finding hosts that are behind on the kernel fixes that attackers are known to use.
The exploited kernel bugs are older fixes
None of the CVEs below is in DSA-6528-1. Each was fixed in an earlier Trixie kernel, which is exactly why they matter here: a host that skipped reboots can carry them for months while the package list looks current.
CVE-2026-53266, ebtables SNAT (CVSS 8.8). ebtables is the firewall for Linux bridges. Its SNAT target can also rewrite the sender hardware address inside ARP packets, and it wrote that address with skb_store_bits() without first making that part of the packet writable. If the bytes were still held in a fragment backed by a page imported with splice, the kernel wrote straight into that page. NVD scores it as a local attack needing only low privileges, and the out-of-bounds write can be used to escalate to root. CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on September 18, with a September 21 deadline for US federal agencies. Debian fixed it in Trixie at 6.12.94-1. Only machines that run an ebtables SNAT rule with ARP rewriting reach the bug.
CVE-2025-39964, AF_ALG race. Concurrent writes to the same kernel crypto socket could corrupt its internal state. Added to KEV the same day; fixed in Trixie at 6.12.57-1.
CVE-2025-39682, kernel TLS receive path. A zero-length record on the receive list skipped the record-type check in recvmsg(). Also added to KEV on September 18; fixed in Trixie at 6.12.48-1 by DSA-6008-1.
CVE-2026-53362, IPv6 paged allocation. A sizing error in __ip6_append_data() that CISA lists as a privilege escalation. Added to KEV on August 27; fixed in Trixie at 6.12.95-1 by DSA-6381-1.
Put as one rule: a Trixie host whose running kernel is older than 6.12.95 is missing at least one KEV-listed fix. CISA has not said who is exploiting these bugs or at what scale, and none of the 1,313 entries in the new advisory has been reported as exploited.
What to do
1. Install the update. The kernel ships under a new package name for each upstream version (linux-image-6.12.111+deb13-amd64, pulled in by the linux-image-amd64 metapackage), so use a full upgrade:
sudo apt update
sudo apt full-upgrade
dpkg -l 'linux-image-*' | grep ^ii
Check the last line shows a 6.12.111-1 package. If you pin kernels or install a specific linux-image-6.12.* package rather than the metapackage, you have to move the pin yourself.
2. Reboot, then prove it took. The new kernel does nothing until the machine boots into it. uname -r shows the ABI name, which should read 6.12.111+deb13-amd64 (or -cloud-amd64, -rt-amd64). uname -v adds the exact Debian package version, for example Debian 6.12.111-1. Across a fleet, needrestart -b -k (from the needrestart package) prints NEEDRESTART-KCUR (running) and NEEDRESTART-KEXP (expected); a NEEDRESTART-KSTA value of 3 means a newer kernel is installed but not running. Collect that from every host; it is the report that finds machines that installed earlier kernels and never restarted.
3. Check individual CVEs against what is installed. apt changelog linux-image-amd64 only shows the metapackage's history; the kernel's own changelog sits in the versioned package, for example apt changelog linux-image-6.12.111+deb13-amd64. For a CVE-level answer, the security tracker page for each CVE gives the fixed version per release, and debsecan --suite trixie --only-fixed lists the CVEs on a host that already have a fix waiting.
4. If a host cannot reboot this week. Debian does not publish live patches for its stable kernels; a 2024 DebConf proposal to add them is still a plan. Commercial live patching services exist, but they ship the fixes their vendor chose to build, not the whole 6.12.111-1 package, so count them as a bridge until the next maintenance window. For CVE-2026-53266, check whether the vulnerable code is even in use: lsmod | grep ebt_snat shows whether the SNAT module is loaded, and ebtables -t nat -L shows any rules using it. Hosts without bridges or ebtables NAT rules do not reach that path.
5. Look for signs on hosts that were behind. For machines that ran a kernel older than 6.12.95 while exposed to untrusted local users, containers or web shells, review new accounts and sudoers changes, unexpected SUID binaries (find / -xdev -perm -4000 -mtime -90), and kernel oops or warning lines in journalctl -k. CISA has published no indicators for these four CVEs, so this is a general check for local privilege escalation, not a signature match.
Measure running kernels, not packages
On Linux servers, "patched" usually gets measured as "package installed", and for the kernel that measure is wrong. All four KEV-listed bugs above were already fixed in packages Debian shipped, the oldest in September 2025. A fleet report that compares running kernel to installed kernel, refreshed after each patch run, catches that gap better than reading advisories.
If you want that report built across your Linux estate, or need help planning reboots for systems that rarely restart, our security operations and safeguarding and hardening teams do this work. Open the chat and Yaali, our AI agent, will pass your question to an engineer.
Sources: Debian DSA-6528-1 announcement, Debian security tracker, DSA-6528-1, Debian security tracker, CVE-2026-53266, 9to5Linux, Cybersecurity News, Mallory, CISA KEV alert, September 18, CISA KEV catalog, LinuxSecurity on CVE-2026-53266, NVD CVE-2026-53266, DebConf 24, live patching in Debian.