<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Trixie on Shadowfish</title><link>https://shadowfish.night-tower.net/tags/trixie/</link><description>Recent content in Trixie on Shadowfish</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><copyright>© 2026 Creeping depths of the deep</copyright><lastBuildDate>Sun, 02 Aug 2026 09:17:49 +0200</lastBuildDate><atom:link href="https://shadowfish.night-tower.net/tags/trixie/index.xml" rel="self" type="application/rss+xml"/><item><title>Debian 13 Trixie Kernel Alert: Updating to 6.12.100+deb13-amd64 Without Losing Your Mind</title><link>https://shadowfish.night-tower.net/post/debian-13-kernel-6-12-cve-update-guide/</link><pubDate>Sun, 02 Aug 2026 09:17:49 +0200</pubDate><guid>https://shadowfish.night-tower.net/post/debian-13-kernel-6-12-cve-update-guide/</guid><description>&lt;div class="my-6 rounded-xl border border-neutral-200 bg-neutral-50/60 p-6 shadow-sm transition-colors dark:border-neutral-700/80 dark:bg-neutral-800/50"&gt;
 
 &lt;div class="mb-4 flex items-center justify-between gap-3 border-b border-neutral-200/80 pb-3 dark:border-neutral-700/80"&gt;
 &lt;div class="flex items-center gap-2.5 font-semibold text-neutral-900 dark:text-neutral-100"&gt;
 
 &lt;span class="text-primary-600 dark:text-primary-400 flex items-center"&gt;
 
 &lt;/span&gt;
 
 
 &lt;span class="text-lg tracking-tight"&gt;The 30-Second Maintenance Promise&lt;/span&gt;
 
 &lt;/div&gt;
 
 &lt;span class="rounded bg-neutral-200/80 px-2.5 py-0.5 text-xs font-medium text-neutral-700 dark:bg-neutral-700 dark:text-neutral-300"&gt;
 TL;DR
 &lt;/span&gt;
 
 &lt;/div&gt;
 

 &lt;div class="prose dark:prose-invert max-w-none text-neutral-700 dark:text-neutral-300"&gt;&lt;p&gt;&lt;strong&gt;Worried that updating your Debian 13 client will take all weekend?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Keeping your workstation or server patched is literally a &lt;strong&gt;2-command affair&lt;/strong&gt;:&lt;/p&gt;
&lt;div class="highlight-wrapper"&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo apt update &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; sudo apt install linux-image-amd64 &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; sudo reboot&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;
&lt;p&gt;That&amp;rsquo;s it! Read on to learn how to check your exact kernel version and verify your system against official security tracker records in under two minutes.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Lazy sysadmin tip:&lt;/em&gt; Want your machine to fetch security patches automatically while you sleep? Check out the official guide on setting up &lt;strong&gt;&lt;a href="https://wiki.debian.org/UnattendedUpgrades" target="_blank" rel="noreferrer"&gt;Debian UnattendedUpgrades&lt;/a&gt;&lt;/strong&gt;.&lt;/p&gt;
&lt;/div&gt;

 
&lt;/div&gt;

&lt;p&gt;It is a quiet Sunday morning. Your &lt;a href="https://shadowfish.night-tower.net/post/night-tower-homelab-architecture/" &gt;Night-Tower homelab&lt;/a&gt; is idling gracefully, CPU temperatures are at a cool 32°C, and you are admiring a pristine 214-day uptime counter on your primary Debian host. You take a triumphant sip of warm coffee, open your browser, and glance at the security security tracker.&lt;/p&gt;
&lt;p&gt;Then it hits you like a rogue DMA packet: a flurry of &lt;strong&gt;CVE security fixes&lt;/strong&gt; just dropped for &lt;strong&gt;Debian 13 (Trixie)&lt;/strong&gt; in kernel package &lt;code&gt;linux-image-6.12.100+deb13-amd64&lt;/code&gt;.&lt;/p&gt;
&lt;div class="highlight-wrapper"&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-text" data-lang="text"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;[ ALERT ] CVE-2026-XXXX: Local Privilege Escalation via obscure subsystem
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;[ ALERT ] CVE-2026-YYYY: Out-of-bounds memory write when handling malformed packets
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;[ STATUS ] Fixed in linux version 6.12.100+deb13-1&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;
&lt;p&gt;Suddenly, your beloved uptime counter feels less like a badge of honor and more like an open invitation to cosmic chaos. But don&amp;rsquo;t panic! Upgrading your kernel and double-checking your security status against Debian&amp;rsquo;s official security tracker is quick, painless, and completely survival-approved.&lt;/p&gt;
&lt;p&gt;Here is your ultra-simple, funny survival guide to staying secure on Debian 13 Trixie.&lt;/p&gt;</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://shadowfish.night-tower.net/post/debian-13-kernel-6-12-cve-update-guide/featured.jpg"/></item></channel></rss>