THE Debian project has released security advisory DSA-6405-1 for Debian 13, addressing 68 kernel vulnerabilities, including four critical ones that result in use-after-free flaws in various subsystems such as net/sched, NVMe/TCP, and SMC-R. Users are urged to upgrade immediately as these vulnerabilities can lead to local privilege escalation, denial of service, and information disclosure. The most severe vulnerabilities include CVE-2026-64530, CVE-2026-64534, CVE-2026-64535, and CVE-2026-64541.
Risk varies based on system configuration, especially for those using NVMe/TCP and SMC-R. Users are advised to install updates without assessing individual exposure and to reboot the system after upgrading to verify the new kernel version.