Linuxsecurity Debian 11 Privilege Escalation Vulnerabilities Addressed in Recent Updates
Article Content
- •Multiple vulnerabilities in Apparmor affect Debian 11 and Trixie distributions.
- •Critical updates released for linux-6.1 and linux packages to address privilege escalation.
- •Users are urged to upgrade their systems immediately to avoid exploitation.
The Qualys Threat Research Unit (TRU) identified multiple vulnerabilities in Apparmor affecting Debian 11 (Bullseye) and the stable distribution (Trixie). For Debian 11, the vulnerabilities have been patched in version 6.1.164-1~deb11u1 for the linux-6.1 packages and version 5.10.251-1 for the linux packages. These updates also address regressions and include additional bug fixes. Users are strongly advised to upgrade their systems to mitigate potential privilege escalation and denial of service risks. The vulnerabilities were disclosed in advisories DLA-4499 and DLA-4498, both published on 2026-03-13. The stable distribution (Trixie) received a fix in version 6.12.74-2 as noted in DSA-6162 on 2026-03-12. The overall impact of these vulnerabilities is significant, as they could allow unauthorized access and control over affected systems.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Debian in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…