Debian 11032 Published by

Debian released three security updates to address critical vulnerabilities in kitty, xen, and ca-certificates. The kitty patch fixes four terminal emulator flaws that could let attackers run arbitrary code or overwrite files through malicious display content. System administrators must upgrade xen to close twenty-seven hypervisor vulnerabilities that risk privilege escalation, data exposure, or service outages. The ca-certificates advisory for Debian 11 and 12 refreshes Mozilla's trusted certificate bundle by adding twenty-four new authorities and removing fifteen expired ones.

[DSA 6423-1] kitty security update
[DSA 6424-1] xen security update
[DLA 4726-1] ca-certificates CA certificate update




[SECURITY] [DSA 6423-1] kitty security update



- -------------------------------------------------------------------------
Debian Security Advisory DSA-6423-1 security@debian.org
https://www.debian.org/security/ Nilesh Patra
August 09, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : kitty
CVE ID : CVE-2026-42850 CVE-2026-42851 CVE-2026-54055 CVE-2026-54057
Debian Bug : 1139898

Multiple security issues were discovered in kitty, a GPU based terminal
emulator, which may result in the execution of arbitrary code, command
injection into the shell running in the terminal, or the overwriting of
arbitrary files, if untrusted content is displayed in a terminal window.

For the stable distribution (trixie), these problems have been fixed in
version 0.41.1-2+deb13u2.

We recommend that you upgrade your kitty packages.

For the detailed security status of kitty please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/kitty

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/


[SECURITY] [DSA 6424-1] xen security update



- -------------------------------------------------------------------------
Debian Security Advisory DSA-6424-1 security@debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
August 09, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : xen
CVE ID : CVE-2025-10263 CVE-2025-54505 CVE-2025-54518 CVE-2026-23554
CVE-2026-23555 CVE-2026-23556 CVE-2026-23557 CVE-2026-23558
CVE-2026-42487 CVE-2026-42488 CVE-2026-42489 CVE-2026-42490
CVE-2026-42493 CVE-2026-42494 CVE-2026-42495 CVE-2026-62423
CVE-2026-62424 CVE-2026-62425 CVE-2026-62426 CVE-2026-62427
CVE-2026-62428 CVE-2026-62429 CVE-2026-62430 CVE-2026-62431
CVE-2026-62432 CVE-2026-62433 CVE-2026-62434 CVE-2026-62435
CVE-2026-62436

Multiple vulnerabilities have been discovered in the Xen hypervisor,
which could result in privilege escalation, information disclosure or
denial of service.

For the stable distribution (trixie), these problems have been fixed in
version 4.20.3+127-gc42374a105-0+deb13u1.

We recommend that you upgrade your xen packages.

For the detailed security status of xen please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/xen

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/


[SECURITY] [DLA 4726-1] ca-certificates CA certificate update



- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4726-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Bastien Roucariès
August 09, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package : ca-certificates
Version : 20250419~deb12u1~deb11u1 20250419~deb12u1
Debian Bug : 981663 1023945 1031490 1032916 1050112 1058658 1063093 1067042

ca-certificates a package that contains the certificate authorities
shipped with Mozilla's browser to allow SSL-based applications to check
for the authenticity of SSL connections, was updated

Mozilla certificate authority bundle was updated to version 2.74

The following certificate authorities were added (+):
+ D-TRUST BR Root CA 2 2023
+ D-TRUST EV Root CA 2 2023
+ Telekom Security TLS ECC Root 2020
+ Telekom Security TLS RSA Root 2023
+ FIRMAPROFESIONAL CA ROOT-A WEB
+ TWCA CYBER Root CA
+ SecureSign Root CA12
+ SecureSign Root CA14
+ SecureSign Root CA15
+ Atos TrustedRoot Root CA ECC TLS 2021
+ Atos TrustedRoot Root CA RSA TLS 2021
+ BJCA Global Root CA1
+ BJCA Global Root CA2
+ CommScope Public Trust ECC Root-01
+ CommScope Public Trust ECC Root-02
+ CommScope Public Trust RSA Root-01
+ CommScope Public Trust RSA Root-02
+ Sectigo Public Server Authentication Root E46
+ Sectigo Public Server Authentication Root R46
+ SSL.com TLS ECC Root CA 2022
+ SSL.com TLS RSA Root CA 2022
+ TrustAsia Global Root CA G3
+ TrustAsia Global Root CA G4
The following certificate authorities were removed (-):
- Entrust Root Certification Authority - G4
- SecureSign RootCA11
- Security Communication RootCA3
- SwissSign Silver CA - G2
- Security Communication Root CA (closes: #1063093)
- Autoridad de Certificacion Firmaprofesional CIF A62634068
- E-Tugra Certification Authority (closes: #1032916)
- E-Tugra Global Root CA ECC v3
- E-Tugra Global Root CA RSA v3
- Hongkong Post Root CA 1
- TrustCor ECA-1
- TrustCor RootCert CA-1
- TrustCor RootCert CA-2 (closes: #1023945)

Please note that Debian can neither confirm nor deny whether the
certificate authorities whose certificates are included in this package
have in any way been audited for trustworthiness or RFC 3647 compliance.
Full responsibility to assess them belongs to the local system administrator.

For Debian 11 bullseye, this problem has been fixed in version
20250419~deb12u1~deb11u1.

For Debian 12 bookworm, this problem has been fixed in version
20250419~deb12u1.

We recommend that you upgrade your ca-certificates packages.

For the detailed security status of ca-certificates please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/ca-certificates

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS