Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To check whether a Debian system is vulnerable to a known CVE, look up the CVE or package in Debian’s Security Tracker, select the release installed on the system, and compare the installed Debian package version with that release’s status and fixed version. Do not rely on the upstream version string alone: Debian may backport a security fix without changing it to the newest upstream version.

1. Identify the CVE or affected package

Start with the CVE identifier if you have one. Otherwise, record the Debian package name mentioned in the security notice, scan, or report. A CVE identifies a vulnerability; it does not, by itself, show whether Debian or a particular Debian release is affected. Debian’s Security Tracker links CVEs with Debian packages, advisories, bugs, and release-specific status. Public tracker information may not include issues still under embargo.

2. Check the status for your Debian release

  1. Open the Debian Security Tracker and search for the CVE or package.

  2. Identify the Debian release, or suite, installed on the system and inspect that release’s entry. Do not use another release’s status or fixed version as a substitute.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  3. Read the package status and any fixed-version information shown for that release. A vulnerability may have different status or remediation versions across Debian releases.

Debian’s tracker is the reference for Debian-specific status. A general vulnerability scanner or outside severity rating can help identify an issue to investigate, but it does not establish that your installed Debian package is vulnerable. Debian says it does not provide CVSS scores or use external CVSS scores in its triage; use the tracker’s package, suite, notes, and version information instead.

3. Find the installed package version

Check the installed Debian package version, not just the upstream software version displayed by an application. Debian can apply security fixes to an older upstream release, so a version that looks old may already include the fix.

Compare the exact Debian package version installed on the machine with the fixed version listed for its release. If the tracker or advisory does not make the status clear, consult the package changelog. Debian’s security FAQ recommends checking the changelog or comparing the exact package version with the version specified in the relevant Debian Security Advisory.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

4. Use debsecan for a broader installed-package check

For a report covering installed packages, rather than one known CVE, Debian’s debsecan tool uses Security Tracker data to report packages that may be vulnerable and where updates are available. Treat its output as a way to find candidates for review, not a replacement for checking the correct release and confirming important findings against the tracker.

5. Apply the Debian fix and verify the affected software

  1. Refresh the available package information using your usual Debian package-management workflow.

  2. Upgrade the affected package or packages to the fixed version available for the installed release.

  3. If a Debian Security Advisory identifies a source package, check which binary packages were built from it and update the relevant ones too; the affected software may not be represented by only one installed binary package.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  4. Restart the affected service or process if the update requires it, so the running software uses the updated files.

  5. Check the installed version again against the release-specific fixed version or package changelog.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

6. Account for support lifecycle and package source

Coverage depends on both the Debian release and where a package comes from. Debian’s FAQ describes stable security support as lasting three years after release. It also says that contrib, non-free, and non-free-firmware are not official parts of the distribution supported by Debian’s security team. Check the actual release and package source rather than assuming that every installed program receives the same security support.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.