Debian Trixie kernel update DSA-6528-1 patches 1,000+ Linux kernel CVEs (privilege escalation, DoS, information leaks)

Debian Trixie kernel update DSA-6528-1 patches 1,000+ Linux (TL-2026-2849), also tracked as DSA-6528-1, is a high-severity software vulnerability, first published 2026-09-29. It has no confirmed attribution, affects Debian Linux kernel (linux source package, trixie), references 20 CVEs (CVE-2024-52560, CVE-2024-58094, CVE-2024-58095), maps to 2 MITRE ATT&CK techniques (T1212, T1499.004), and is covered by 9 detection rules and 3 indicators of compromise.

Key facts for TL-2026-2849

Threat ID
TL-2026-2849
Also known as
DSA-6528-1
Severity
HIGH
Status
PATCHED
Category
VULNERABILITY
First published
2026-09-29
Last reviewed
2026-09-29
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, government administration, finance, health, telecoms
Target regions
Global
Detection rules
9
Indicators of compromise
3

Debian published DSA-6528-1 on 2026-09-29, updating the Trixie Linux kernel from 6.12.107-1 to 6.12.111-1. The advisory states the fixed flaws may lead to privilege escalation, denial of service or information leaks. No in-the-wild exploitation is reported for the advisory itself.

How Debian Trixie kernel update DSA-6528-1 patches 1,000+ Linux works

Debian Security Advisory DSA-6528-1 ('[SECURITY] [DSA 6528-1] linux security update', 2026-09-29) updates the linux source package for Debian stable 'trixie' to 6.12.111-1. The advisory text says 'several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks' and tells users to upgrade their linux packages.

The CVE count is reported inconsistently across sources: the Cyber Security News article reports 1,313 CVE entries, the Debian security-announce list page showed 1,053 identifiers, and the Debian security tracker DSA page showed 1,199. The count should be treated as 'roughly 1,000-1,300' until the tracker is re-checked. The identifiers span the 2024, 2025 and 2026 CVE namespaces. The Debian advisory carries no per-CVE descriptions or CVSS scores.

Examples confirmed against the Debian tracker/NVD: CVE-2024-52560 (NTFS3 mi_enum_attr() inode-marking fix, NVD CVSS 5.5, kernel 5.15 to 6.13.3 affected); CVE-2025-21817 (block-layer sysfs store() deadlock via GFP_KERNEL allocation while the queue is frozen, CVSS 5.5, CWE-667); CVE-2025-22104 (ibmvnic hex-dump buffer over-read); CVE-2026-23137 (device-tree unittest_data_add() memory leak); CVE-2026-100079 (USB Type-C UCSI debugfs entries not removed on unregister; the tracker cites DSA-6528-1). The sampled flaws are mostly local, low-to-medium severity kernel bugs; the aggregate advisory is rated HIGH by analyst estimate because it bundles privilege-escalation-class fixes.

Exploitation context: neither the article nor the advisory reports exploitation of DSA-6528-1 flaws. Separately, CISA's KEV catalog recently added several Linux kernel CVEs (2026-08-26 to 2026-09-18), including CVE-2025-39964 (af_alg concurrent writes), CVE-2026-53266 (ebtables SNAT ARP rewrite on splice-imported page) and CVE-2025-39682 (TLS receive path). The Debian tracker lists 6.12.111-1 as a fixed trixie version for the first two, but did not list DSA-6528-1 for them and shows 6.12.107-1 as already fixed. Whether these KEV entries ship via this DSA is therefore unconfirmed. Hosts still on 6.12.107-1 or earlier should be treated as exposed to the KEV-listed kernel flaws regardless.

Remediation is a normal package upgrade followed by a reboot into the new kernel; verify with uname -r.

MITRE ATT&CK techniques used in TL-2026-2849

Credential Access

T1212 Exploitation for Credential Access

Impact

T1499.004 Endpoint Denial of Service: Application or System Exploitation

Affected products and versions in Debian Trixie kernel update DSA-6528-1 patches 1,000+ Linux

  • Debian — Linux kernel (linux source package, trixie)
    Vulnerable versions: 6.12.107-1 and earlier
    Fixed in: 6.12.111-1

Remediation for Debian Trixie kernel update DSA-6528-1 patches 1,000+ Linux

Patches

  • Debian trixie linux 6.12.111-1 (DSA-6528-1)

Immediate actions

  • Run sudo apt-get update && sudo apt-get upgrade on Debian trixie hosts to install linux 6.12.111-1
  • Reboot into the updated kernel and confirm with uname -r
  • Prioritise internet-facing, multi-tenant and container hosts for the kernel update

Workarounds

  • No workaround stated in the advisory; upgrade the linux packages

Longer-term hardening

  • Track Debian security-announce and the Debian security tracker for linux kernel DSAs
  • Monitor CISA KEV for Linux kernel additions and map them to fleet kernel versions
  • Maintain a kernel patch SLA and live-patch or reboot-window process

CVEs associated with Debian Trixie kernel update DSA-6528-1 patches 1,000+ Linux

  • CVE-2024-52560
  • CVE-2024-58094
  • CVE-2024-58095
  • CVE-2025-21817
  • CVE-2025-22104
  • CVE-2025-22108
  • CVE-2025-22127
  • CVE-2025-38203
  • CVE-2025-38205
  • CVE-2025-38206
  • CVE-2025-40168
  • CVE-2026-23137
  • CVE-2026-43198
  • CVE-2026-53010
  • CVE-2026-64058
  • CVE-2026-100070
  • CVE-2026-100071
  • CVE-2026-100075
  • CVE-2026-100078
  • CVE-2026-100079

Weaknesses (CWE) in Debian Trixie kernel update DSA-6528-1 patches 1,000+ Linux

CWE-667

Timeline of Debian Trixie kernel update DSA-6528-1 patches 1,000+ Linux

  • CISA added Linux kernel CVE-2022-0995 to the KEV catalog (kernel exploitation context for fleet patching; not stated as part of DSA-6528-1)
  • CISA added Linux kernel IPv6 networking flaw CVE-2026-53362 (privilege escalation) to KEV; not confirmed as part of DSA-6528-1
  • CISA added Linux kernel CVE-2025-39964 (af_alg), CVE-2026-53266 (ebtables SNAT) and CVE-2025-39682 (TLS receive path) to KEV; Debian tracker lists 6.12.111-1 as a fixed trixie version for the first two
  • Fixed linux 6.12.111-1 available via trixie security; Debian tracker cites DSA-6528-1 for CVE-2026-100079
  • Debian published DSA-6528-1 updating trixie linux from 6.12.107-1 to 6.12.111-1 for privilege escalation, DoS and information-leak flaws
  • Cyber Security News reported 1,313 CVEs in the update and no in-the-wild exploitation; Debian pages show 1,053 to 1,199 CVE identifiers

Sources cited for Debian Trixie kernel update DSA-6528-1 patches 1,000+ Linux

More in vulnerability

Detection coverage for TL-2026-2849

As of 2026-09-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2849 across Splunk SPL, Microsoft KQL and Sigma, covering 3 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats