The Debian project has released Debian 12.14, the fourteenth update to its oldstable distribution, Bookworm. This point release is a maintenance update that incorporates numerous security advisories and fixes for serious problems.
Unlike a new major version, 12.14 does not constitute a new version of Debian 12 but only updates some of the packages included. Existing installations can be upgraded by pointing the package manager to an up-to-date Debian mirror. The update includes fixes for critical components such as OpenSSH, OpenSSL, and the Linux kernel.
Notable security fixes address vulnerabilities in OpenSSH (CVE-2025-61984, CVE-2026-35386), Apache2, and the web browser stack (Chromium, Firefox ESR). The update also patches the system core, including systemd (CVE-2026-40225, CVE-2026-40226) and glibc.
Several packages were removed from the repository due to security concerns or lack of maintenance, including suricata and zulucrypt.
A comprehensive list of all packages updated and the specific CVEs addressed is available in the official ChangeLog.