Debian 11009 Published by

Debian Long Term Support and Freexian Extended advisories released security patches addressing serious flaws in the linux-6.1 kernel, hplip printing software, BIND9 DNS server, and php-phpseclib cryptography library. The update for linux-6.1 closes more than fifty vulnerabilities that could enable privilege escalation or information disclosure on Debian 11 systems while also incorporating changes to the Azure Network Adapter driver. Additional fixes resolve arbitrary code execution risks in HP's printing tools across multiple distributions and repair DNSSEC bypass, cache poisoning, and denial of service weaknesses in BIND9 for older releases.

[DLA 4700-1] linux-6.1 security update
[DLA 4699-1] hplip security update
ELA-1784-1 hplip security update
ELA-1786-1 bind9 security update
ELA-1785-1 php-phpseclib security update (by )




[SECURITY] [DLA 4700-1] linux-6.1 security update


-------------------------------------------------------------------------
Debian LTS Advisory DLA-4700-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Ben Hutchings
July 26, 2026 https://wiki.debian.org/LTS
-------------------------------------------------------------------------

Package : linux-6.1
Version : 6.1.177-1~deb11u1
CVE ID : CVE-2025-23131 CVE-2026-23272 CVE-2026-23278 CVE-2026-23302
CVE-2026-31451 CVE-2026-46252 CVE-2026-52928 CVE-2026-53138
CVE-2026-53139 CVE-2026-53157 CVE-2026-53158 CVE-2026-53163
CVE-2026-53167 CVE-2026-53325 CVE-2026-53327 CVE-2026-53359
CVE-2026-53362 CVE-2026-53366 CVE-2026-53381 CVE-2026-53382
CVE-2026-53383 CVE-2026-53384 CVE-2026-53385 CVE-2026-53388
CVE-2026-53390 CVE-2026-53391 CVE-2026-53397 CVE-2026-53398
CVE-2026-53403 CVE-2026-63794 CVE-2026-63795 CVE-2026-63796
CVE-2026-63798 CVE-2026-63800 CVE-2026-63801 CVE-2026-63803
CVE-2026-63807 CVE-2026-63808 CVE-2026-63809 CVE-2026-63814
CVE-2026-63817 CVE-2026-63822 CVE-2026-63823 CVE-2026-63824
CVE-2026-63827 CVE-2026-63828 CVE-2026-63830 CVE-2026-63831
CVE-2026-63833 CVE-2026-63834 CVE-2026-63835 CVE-2026-63836
CVE-2026-64188 CVE-2026-64191 CVE-2026-64246 CVE-2026-64249
CVE-2026-64252 CVE-2026-64254 CVE-2026-64529
Debian Bug : 1130365

Several vulnerabilities have been discovered in the Linux kernel that
may lead to a privilege escalation, denial of service or information
leaks.

For Debian 11 bullseye, these problems have been fixed in version
6.1.177-1~deb11u1. This version additionally updates the Microsoft
Azure Network Adapter (mana) driver, and includes many more bug fixes
from stable update 6.1.177.

We recommend that you upgrade your linux-6.1 packages.

For the detailed security status of linux-6.1 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/linux-6.1

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



[SECURITY] [DLA 4699-1] hplip security update



- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4699-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Thorsten Alteholz
July 25, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package : hplip
Version : 3.21.2+dfsg1-2+deb11u1 3.22.10+dfsg0-2+deb12u1
CVE ID : CVE-2026-8631 CVE-2026-8632
Debian Bug : 1137374

Two issues have been found in hplip, the HP Linux Printing and Imaging
System. They are both related to privilege escalation and/or arbitrary
code execution.

For Debian 11 bullseye, these problems have been fixed in version
3.21.2+dfsg1-2+deb11u1.

For Debian 12 bookworm, these problems have been fixed in version
3.22.10+dfsg0-2+deb12u1.

We recommend that you upgrade your hplip packages.

For the detailed security status of hplip please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/hplip

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


ELA-1784-1 hplip security update (by )


Package : hplip

Version : 3.16.11+repack0-3+deb9u2 (stretch), 3.18.12+dfsg0-2+deb10u2 (buster)

Related CVEs :
CVE-2026-8631
CVE-2026-8632

Two issues have been found in hplip, the HP Linux Printing and Imaging
System. They are both related to privilege escalation and/or arbitrary
code execution.


ELA-1784-1 hplip security update (by )



ELA-1786-1 bind9 security update (by )


Package : bind9

Version : 1:9.11.37+git20260722.018aa2e+dfsg-0~deb10u1 (buster)

Related CVEs :
CVE-2025-8677
CVE-2026-1519
CVE-2026-3039
CVE-2026-3592
CVE-2026-5946
CVE-2026-5950
CVE-2026-10723
CVE-2026-11622
CVE-2026-11721
CVE-2026-13204
CVE-2026-13321

Several vulnerabilities were discovered in BIND, a DNS server
implementation, which may result in bypass of DNSSEC validation, RPZ
policy bypass, cache poisoning or denial of service.


ELA-1786-1 bind9 security update (by )



ELA-1785-1 php-phpseclib security update (by )


Package : php-phpseclib

Version : 2.0.30-2~deb10u4 (buster)

Related CVEs :
CVE-2023-52892
CVE-2026-32935
CVE-2026-40194
CVE-2026-44167
CVE-2026-55599

Several vulnerabilities were discovered in phpseclib, a PHP secure
communications library, which could result in hostname validation
bypass, timing side-channel attacks, denial of service, and
server-side request forgery (SSRF).
CVE-2023-52892
X509.php did not properly escape regular expression special
characters in a certificate's subjectAltName, allowing a crafted
certificate to bypass hostname validation in validateURL().

CVE-2026-32935
The block cipher unpadding routine in Crypt/Base.php used a
short-circuiting comparison, creating a timing side channel that
could aid padding-oracle-style attacks.

CVE-2026-40194
The SSH2 implementation compared incoming packet HMACs using a
variable-time string comparison, creating a timing side channel
on cryptographic material.

CVE-2026-44167
The ASN.1 decoder's 4096-byte Object Identifier limit (mitigating
CVE-2024-27355) was still large enough to allow an "OID
amplification" denial of service via crafted ASN.1 structures.

CVE-2026-55599
File_X509 could automatically fetch a URL from a certificate's
Authority Information Access extension without validating the
destination, allowing SSRF via a crafted certificate.


ELA-1785-1 php-phpseclib security update (by )