The Debian Project has released the seventh point release of its stable distribution: Debian 13.7 for “trixie”.
A point release doesn’t bring a new Debian version, but rather over 150 package updates fixing security issues and serious bugs. Existing installation media don’t need to be discarded, updates can be applied through the regular package manager.
Among the most important fixes are security issues in the Linux kernel, OpenSSL, ImageMagick, QEMU, Samba, glibc and curl, plus numerous other libraries and tools.
This point release mainly adds corrections for security issues, along with a few adjustments for serious problems.
Miscellaneous Bugfixes (excerpt):
- glibc: Fix buffer overflow/underflow issues [CVE-2026-5928 CVE-2026-5450]
- openssl: New upstream release
- imagemagick: Fix buffer overflow, use-after-free and information disclosure issues (multiple CVEs)
- qemu: New upstream stable release; fix integer overflow, secure boot bypass and use-after-free issues (multiple CVEs)
- samba: New upstream stable release
- curl: Fix OpenSSL engine loading return value
- libvirt: Fix buffer overflow, privilege escalation and information disclosure issues (multiple CVEs)
- python3.13: Fix use-after-free in dict.clear(); fix injection and file overwrite issues
Additionally, 98 Debian Security Advisories (DSA-6381 through DSA-6486) were already published before this release, covering Linux, Firefox, Chromium, OpenJDK and others.

The full changelog is available at the Debian ChangeLog, a list of mirrors at debian.org/mirror/list.
Source: Debian