Debian Trixie kernel update DSA-6528-1 patches 1,000+ Linux kernel CVEs (privilege escalation, DoS, information leaks)
Debian Trixie kernel update DSA-6528-1 patches 1,000+ Linux (TL-2026-2849), also tracked as DSA-6528-1, is a high-severity software vulnerability, first published 2026-09-29. It has no confirmed attribution, affects Debian Linux kernel (linux source package, trixie), references 20 CVEs (CVE-2024-52560, CVE-2024-58094, CVE-2024-58095), maps to 2 MITRE ATT&CK techniques (T1212, T1499.004), and is covered by 9 detection rules and 3 indicators of compromise.
Key facts for TL-2026-2849
- Threat ID
- TL-2026-2849
- Also known as
- DSA-6528-1
- Severity
- HIGH
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- 2026-09-29
- Last reviewed
- 2026-09-29
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, government administration, finance, health, telecoms
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 3
Debian published DSA-6528-1 on 2026-09-29, updating the Trixie Linux kernel from 6.12.107-1 to 6.12.111-1. The advisory states the fixed flaws may lead to privilege escalation, denial of service or information leaks. No in-the-wild exploitation is reported for the advisory itself.
How Debian Trixie kernel update DSA-6528-1 patches 1,000+ Linux works
Debian Security Advisory DSA-6528-1 ('[SECURITY] [DSA 6528-1] linux security update', 2026-09-29) updates the linux source package for Debian stable 'trixie' to 6.12.111-1. The advisory text says 'several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks' and tells users to upgrade their linux packages.
The CVE count is reported inconsistently across sources: the Cyber Security News article reports 1,313 CVE entries, the Debian security-announce list page showed 1,053 identifiers, and the Debian security tracker DSA page showed 1,199. The count should be treated as 'roughly 1,000-1,300' until the tracker is re-checked. The identifiers span the 2024, 2025 and 2026 CVE namespaces. The Debian advisory carries no per-CVE descriptions or CVSS scores.
Examples confirmed against the Debian tracker/NVD: CVE-2024-52560 (NTFS3 mi_enum_attr() inode-marking fix, NVD CVSS 5.5, kernel 5.15 to 6.13.3 affected); CVE-2025-21817 (block-layer sysfs store() deadlock via GFP_KERNEL allocation while the queue is frozen, CVSS 5.5, CWE-667); CVE-2025-22104 (ibmvnic hex-dump buffer over-read); CVE-2026-23137 (device-tree unittest_data_add() memory leak); CVE-2026-100079 (USB Type-C UCSI debugfs entries not removed on unregister; the tracker cites DSA-6528-1). The sampled flaws are mostly local, low-to-medium severity kernel bugs; the aggregate advisory is rated HIGH by analyst estimate because it bundles privilege-escalation-class fixes.
Exploitation context: neither the article nor the advisory reports exploitation of DSA-6528-1 flaws. Separately, CISA's KEV catalog recently added several Linux kernel CVEs (2026-08-26 to 2026-09-18), including CVE-2025-39964 (af_alg concurrent writes), CVE-2026-53266 (ebtables SNAT ARP rewrite on splice-imported page) and CVE-2025-39682 (TLS receive path). The Debian tracker lists 6.12.111-1 as a fixed trixie version for the first two, but did not list DSA-6528-1 for them and shows 6.12.107-1 as already fixed. Whether these KEV entries ship via this DSA is therefore unconfirmed. Hosts still on 6.12.107-1 or earlier should be treated as exposed to the KEV-listed kernel flaws regardless.
Remediation is a normal package upgrade followed by a reboot into the new kernel; verify with uname -r.
MITRE ATT&CK techniques used in TL-2026-2849
Credential Access
T1212 Exploitation for Credential Access
Impact
T1499.004 Endpoint Denial of Service: Application or System Exploitation
Affected products and versions in Debian Trixie kernel update DSA-6528-1 patches 1,000+ Linux
- Debian — Linux kernel (linux source package, trixie)
Vulnerable versions: 6.12.107-1 and earlier
Fixed in: 6.12.111-1
Remediation for Debian Trixie kernel update DSA-6528-1 patches 1,000+ Linux
Patches
- Debian trixie linux 6.12.111-1 (DSA-6528-1)
Immediate actions
- Run sudo apt-get update && sudo apt-get upgrade on Debian trixie hosts to install linux 6.12.111-1
- Reboot into the updated kernel and confirm with uname -r
- Prioritise internet-facing, multi-tenant and container hosts for the kernel update
Workarounds
- No workaround stated in the advisory; upgrade the linux packages
Longer-term hardening
- Track Debian security-announce and the Debian security tracker for linux kernel DSAs
- Monitor CISA KEV for Linux kernel additions and map them to fleet kernel versions
- Maintain a kernel patch SLA and live-patch or reboot-window process
CVEs associated with Debian Trixie kernel update DSA-6528-1 patches 1,000+ Linux
CVE-2024-52560CVE-2024-58094CVE-2024-58095CVE-2025-21817CVE-2025-22104CVE-2025-22108CVE-2025-22127CVE-2025-38203CVE-2025-38205CVE-2025-38206CVE-2025-40168CVE-2026-23137CVE-2026-43198CVE-2026-53010CVE-2026-64058CVE-2026-100070CVE-2026-100071CVE-2026-100075CVE-2026-100078CVE-2026-100079
Weaknesses (CWE) in Debian Trixie kernel update DSA-6528-1 patches 1,000+ Linux
CWE-667
Timeline of Debian Trixie kernel update DSA-6528-1 patches 1,000+ Linux
- CISA added Linux kernel CVE-2022-0995 to the KEV catalog (kernel exploitation context for fleet patching; not stated as part of DSA-6528-1)
- CISA added Linux kernel IPv6 networking flaw CVE-2026-53362 (privilege escalation) to KEV; not confirmed as part of DSA-6528-1
- CISA added Linux kernel CVE-2025-39964 (af_alg), CVE-2026-53266 (ebtables SNAT) and CVE-2025-39682 (TLS receive path) to KEV; Debian tracker lists 6.12.111-1 as a fixed trixie version for the first two
- Fixed linux 6.12.111-1 available via trixie security; Debian tracker cites DSA-6528-1 for CVE-2026-100079
- Debian published DSA-6528-1 updating trixie linux from 6.12.107-1 to 6.12.111-1 for privilege escalation, DoS and information-leak flaws
- Cyber Security News reported 1,313 CVEs in the update and no in-the-wild exploitation; Debian pages show 1,053 to 1,199 CVE identifiers
Sources cited for Debian Trixie kernel update DSA-6528-1 patches 1,000+ Linux
- Debian has Patched 1,313 Flaws in Massive Update Leading to DoS and Privilege Escalation Attacks
- [SECURITY] [DSA 6528-1] linux security update (debian-security-announce)
- Debian Security Tracker: DSA-6528-1
- Debian Security Tracker: CVE-2026-100079
- Debian Security Tracker: CVE-2026-23137
- Debian Security Tracker: CVE-2025-22104
- NVD: CVE-2025-21817
- NVD: CVE-2024-52560
- CISA Known Exploited Vulnerabilities Catalog
- Debian Security Tracker: CVE-2026-53266
- Debian Security Tracker: CVE-2025-39964
More in vulnerability
- Critical Capacitor WebView Navigation Guard Bypass Lets Malicious Links Access App Data and Native Features (CVE-2026-103922)
- Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any @icloud.com Sender and Pass SPF/DKIM/DMARC
- Red Hat Satellite Foreman template preview authorization flaw (CVE-2026-96659) enables root password theft and code execution
- Rejetto HTTP File Server (HFS) 3.x session forgery via predictable Math.random() signing key leads to unauthenticated admin access and RCE (CVE-2026-61500) under active exploitation
- Microsoft Reissues September 2026 Exchange Server Updates (V2) for CVE-2026-96940 Mailbox Authorization Flaw
Detection coverage for TL-2026-2849
As of 2026-09-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2849 across Splunk SPL, Microsoft KQL and Sigma, covering 3 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.