Debian 12 “Bookworm” left regular security support on 12 July 2026. It now gets Long Term Support until 30 June 2028, but LTS covers fewer packages and fewer architectures, and the Debian project itself encourages users to move to Debian 13 “Trixie”.
The upgrade is a single apt operation on paper. In practice, the failures come from a handful of changes in Trixie that the official release notes list but most quick guides skip: an SSH bug that can lock you out of a remote server mid-upgrade, network interfaces that can come back with a new name after the reboot, a /boot partition that is suddenly too small, and /etc/sysctl.conf being silently ignored.
This guide follows the official Debian 13 upgrade procedure and puts those traps where you will actually see them: before you start.
Quick answer
- Fully update Debian 12 and reboot:
sudo apt update && sudo apt full-upgrade - Run the pre-flight checks below (SSH version,
/bootspace, architecture, third-party repos). - Replace your APT sources with a
debian.sourcesfile that points attrixie. - Inside
tmuxorscreen:sudo apt update, thensudo apt upgrade --without-new-pkgs, thensudo apt full-upgrade. - Check the network interface name before rebooting, reboot, then verify with
cat /etc/debian_version.
Should you upgrade now?
For most systems, yes. But there are cases where staying on Debian 12 LTS for now is the right call.
| Your situation | Recommendation | Why |
|---|---|---|
| Desktop or laptop on amd64 / arm64 | Upgrade | Low risk, and you keep getting full security support. |
| VPS or server with console access from your provider | Upgrade, after a snapshot | A snapshot plus console access means any network problem after reboot is recoverable. |
| Remote server with SSH only and no console | Upgrade carefully, or wait | If networking does not come back after the reboot, you have no way in. Arrange console or rescue access first. |
| 32-bit i386 system | Do not upgrade | Trixie has no i386 kernel or installer. Debian recommends reinstalling as amd64 or retiring the hardware. Debian 12 LTS still covers i386 until June 2028. |
| Running Dovecot, RabbitMQ, strongSwan or Samba AD | Plan the service migration first | These have incompatible configuration or upgrade paths in Trixie (details in the checklist below). |
| Still on Debian 11 | Upgrade to 12 first | Skipping releases is not supported. Debian 11 LTS ended on 31 August 2026. |
The pre-flight checklist: what actually breaks
Every item below comes from the official “Issues to be aware of for trixie” chapter. Run the check command next to each one. Most systems will pass all of them, but the ones that fail are the ones that turn a 20-minute job into a recovery session.
| Risk | Who it affects | Check before upgrading |
|---|---|---|
| Lockout during a remote upgrade. A bug in Bookworm’s OpenSSH can make a server unreachable if an upgrade over SSH is interrupted. | Anyone upgrading over SSH | dpkg -l openssh-serverVersion must be 1:9.2p1-2+deb12u7 or newer. Fully updating Debian 12 first takes care of it. |
| /boot too small. Kernel and firmware packages have grown. | Systems with a separate /boot, especially ones installed with Debian 10 or older |
df -h /bootNeeds at least 768 MB in size with about 300 MB free. |
| No i386 support. | 32-bit installs | dpkg --print-architectureIf it prints i386, stop here. |
| Network interface may be renamed after the reboot, which breaks static network configuration. | Systems using the i40e NIC driver, or firmware that exposes the ACPI _SUN object |
Checked after the upgrade but before the reboot (Step 8 below). |
| DSA SSH keys stop working. OpenSSH 9.8 in Trixie removes DSA entirely. | Anyone still logging in with a DSA key | ssh -v user@server and look at the “Server accepts key” line. Switch to Ed25519 before upgrading. |
/etc/sysctl.conf is ignored. |
Servers that set kernel parameters there, such as net.ipv4.ip_forward on a router or VPN host |
grep -v '^#' /etc/sysctl.conf | grep .Move any active lines into a file under /etc/sysctl.d/. |
/tmp moves to RAM (tmpfs, up to 50% of memory) after the first reboot. |
Anything that writes large files to /tmp |
du -sh /tmpPoint big jobs elsewhere, or resize with systemctl edit tmp.mount. |
| MariaDB major upgrade (10.11 to 11.8) only recovers cleanly from a clean shutdown. | Database servers | Stop MariaDB yourself before the upgrade and confirm “Shutdown complete” in its log. |
| Dovecot 2.4 uses an incompatible configuration format; RabbitMQ has no direct upgrade path. | Mail servers, message queues | Port the configuration in a test environment first. |
| Third-party repositories may conflict or be removed. | Systems with Docker, PHP (Sury), Node.js, Grafana and similar repos | ls /etc/apt/sources.list.d/Disable them for the upgrade, then re-enable their Trixie versions afterwards. |
Step 1: Back up first
On a VPS, take a provider snapshot. It is the only true rollback: Debian does not support downgrading back to Bookworm after an upgrade.
At minimum, save your configuration and the list of installed packages:
sudo tar czf ~/etc-backup-$(date +%F).tar.gz /etc
dpkg --get-selections '*' > ~/package-selections.txt
sudo cp /var/lib/apt/extended_states ~/apt-extended_states.bak
Copy those files off the machine before you continue.
Step 2: Bring Debian 12 fully up to date
The upgrade assumes you start from the latest Bookworm point release. Half-applied updates become conflicts later.
sudo apt update
sudo apt full-upgrade
cat /etc/debian_version
The version should start with 12.. If a new kernel was installed, reboot now so you start the upgrade from a clean state. This step also brings OpenSSH up to the fixed version mentioned in the checklist.
Step 3: Clean up anything that is not pure Debian
The official procedure is designed for “pure” Debian systems. These commands, from the release notes, find the things that cause most failed upgrades:
# packages in a broken or half-configured state (should print nothing)
sudo dpkg --audit
# packages on hold (holds block the upgrade)
apt-mark showhold
# installed packages that did not come from Debian
apt list '?narrow(?installed, ?not(?origin(Debian)))'
# leftover config files from earlier upgrades
sudo find /etc -name '*.dpkg-*' -o -name '*.ucf-*' -o -name '*.merge-error'
Release any holds with sudo apt-mark unhold package_name, and remove bookworm-backports and proposed-updates entries from your sources.
Step 4: Start a session that survives disconnects
If you are connected over SSH, run the rest of the upgrade inside tmux or screen. If your connection drops, the upgrade keeps running and you can reattach.
sudo apt install tmux
tmux new -s upgrade
If you get disconnected, log back in and run tmux attach -t upgrade.
Step 5: Point APT at Trixie
Trixie ships APT 3.0 and moves APT configuration to the newer deb822 format, a .sources file instead of sources.list. You can switch now, during the upgrade, which is what the release notes recommend.
First move the old configuration out of the way:
sudo mv /etc/apt/sources.list /etc/apt/sources.list.bookworm.bak
Then create the new file:
sudo nano /etc/apt/sources.list.d/debian.sources
Paste this, which is the official example from the release notes:
Types: deb
URIs: https://deb.debian.org/debian
Suites: trixie trixie-updates
Components: main non-free-firmware
Signed-By: /usr/share/keyrings/debian-archive-keyring.gpg
Types: deb
URIs: https://security.debian.org/debian-security
Suites: trixie-security
Components: main non-free-firmware
Signed-By: /usr/share/keyrings/debian-archive-keyring.gpg
Add contrib non-free to both Components: lines if you use packages from those components. Then disable any third-party .list files in /etc/apt/sources.list.d/ by renaming them with a .disabled suffix.
Shortcut you will see elsewhere: sudo sed -i 's/bookworm/trixie/g' /etc/apt/sources.list also works, because Trixie still reads the old format. If you use it, check the result by hand, then convert to the new format after the upgrade with sudo apt modernize-sources.
Make sure no file still mentions Bookworm:
grep -r bookworm /etc/apt/sources.list* 2>/dev/null
Step 6: Refresh the package list and check disk space
sudo apt update
sudo apt -o APT::Get::Trivial-Only=true full-upgrade
The second command changes nothing. It only prints how much will be downloaded and how much extra disk space the upgrade needs. If space is tight, sudo apt clean clears the package cache, and sudo apt autoremove removes unused dependencies.
If this command errors out, that is normal at this stage on some systems. Continue with the minimal upgrade and run it again afterwards.
Step 7: Run the upgrade in two stages
The release notes recommend a minimal upgrade first. It upgrades everything that can be upgraded without installing or removing packages, which avoids large, unexpected removals in the main step.
sudo apt upgrade --without-new-pkgs
Then the full upgrade:
sudo apt full-upgrade
Read the list of packages APT proposes to remove before you press Y. If it wants to remove something important, such as your web server or database, stop and investigate rather than accepting.
Answering configuration file prompts
During the upgrade, dpkg will ask what to do with configuration files you have changed. A practical rule:
- Files you edited on purpose (for example
/etc/ssh/sshd_config, your Nginx or PHP settings): keep your version, then compare it with the new default later. Press D to see the difference before deciding. - Files you never touched: accept the package maintainer’s version.
- Unsure: keep your version and note the file name. The new default is saved alongside it with a
.dpkg-distsuffix, and the whole session is logged in/var/log/apt/term.log.
If apt-listchanges opens a pager with news about changed packages, press q to continue.
Step 8: Checks to do before you reboot
The formal upgrade is finished when apt full-upgrade completes. Before rebooting a remote machine, spend two minutes on these.
Confirm your network interface keeps its name. Replace enp1s0 with your interface from ip -br link:
udevadm test-builtin net_setup_link /sys/class/net/enp1s0 2>/dev/null | grep ID_NET_NAME
If ID_NET_NAME shows a different name from the current one, your static network configuration will point at an interface that no longer exists after reboot. Either update the interface name in /etc/network/interfaces now, or pin the current name with a systemd.link file.
Make sure a kernel metapackage is installed so you actually boot the new kernel:
dpkg -l 'linux-image*' | grep ^ii | grep -i meta
No output means you need one, typically sudo apt install linux-image-amd64. For checking and updating kernels later, see how to update the kernel on Debian.
Encrypted disks: make sure systemd-cryptsetup is installed (dpkg -l systemd-cryptsetup), or encrypted filesystems will not be unlocked at boot.
Step 9: Reboot and verify
sudo reboot
Once you are back in:
cat /etc/debian_version # should start with 13.
uname -r # new kernel version
systemctl --failed # should list 0 failed units
ip -br addr # interfaces up with the expected addresses
journalctl -p err -b # errors from this boot
Then check the services the machine exists for: open your website, send a test email, connect to your database.
Step 10: Clean up
# remove dependencies that are no longer needed
sudo apt autoremove
# convert any remaining old-style source files to deb822
sudo apt modernize-sources
# list packages no longer in Debian, and removed packages with leftover config
apt list '?obsolete'
apt list '?config-files'
Re-enable your third-party repositories one at a time, pointing each at its Trixie (Debian 13) repository rather than Bookworm.
Fixing common upgrade errors
| Error or symptom | Cause | Fix |
|---|---|---|
E: Could not perform immediate configuration on 'package' |
Dependency ordering problem | Run sudo apt full-upgrade -o APT::Immediate-Configure=0 |
trying to overwrite '...', which is also in package ... |
File conflict, usually from an unofficial backport | Remove the package named on the last line of the error with sudo dpkg -r --force-depends package_name, then rerun the upgrade |
dpkg: warning: unable to delete old directory ... |
The final stage of the usrmerge transition | Harmless. The release notes say these warnings can be ignored |
| Packages shown as “held back” | They need other packages added or removed | sudo apt install package_name for each one |
| No network after reboot | Interface renamed, or a third-party network config | Use the provider console, run ip -br link and update the name in your network configuration |
ping: socket: Operation not permitted for normal users |
Ping no longer runs with elevated privileges; linux-sysctl-defaults was not installed |
sudo apt install linux-sysctl-defaults |
A setting in /etc/sysctl.conf no longer applies |
Trixie no longer reads that file | Move the line to /etc/sysctl.d/99-local.conf and run sudo sysctl --system |
last or lastlog: command not found |
Removed in Trixie (Year 2038 problem) | Use lslogins, or install wtmpdb and lastlog2 |
System is tainted: unmerged-bin in the boot log |
systemd noting separate /usr/bin and /usr/sbin |
Ignore it. Do not merge the directories by hand |
What is different on Debian 13 day to day
A few changes will show up in everyday commands, including in older tutorials written for Debian 12:
dnsutilsis gone. On Debian 12 it was a transitional package; on Debian 13 it no longer exists. Installbind9-dnsutilsto getdigandnslookup. See our guides for dig and nslookup.- APT 3.0 has a new output layout and the
apt modernize-sourcescommand. /tmpis a tmpfs and is cleared on reboot.- Kernel settings belong in
/etc/sysctl.d/, not/etc/sysctl.conf. - Networking is still configured the same way. Servers keep using
/etc/network/interfaceswith ifupdown, and desktops keep using NetworkManager. Our static IP guide covers both releases.
Frequently asked questions
Can I upgrade from Debian 11 directly to Debian 13?
No. Skipping releases is not supported, and Trixie’s usrmerge changes require a completed Bookworm upgrade first. Upgrade 11 to 12, reboot, then 12 to 13.
Can I roll back if something goes wrong?
Not with apt. Debian does not support downgrades. Your rollback options are a VM or VPS snapshot taken before the upgrade, or a reinstall plus the backups from Step 1.
Do I have to switch to the deb822 .sources format?
Not immediately. Trixie still reads sources.list, but the old format is deprecated, so converting now with apt modernize-sources saves work before Debian 14.
How do I confirm the upgrade worked?
cat /etc/debian_version shows 13.x, and cat /etc/os-release shows VERSION_CODENAME=trixie.
Is staying on Debian 12 safe?
Until 30 June 2028, through Debian LTS, with limits: some packages are not covered. Install debian-security-support to see which of your installed packages are not.
Sources
- Debian 13 Release Notes, Chapter 4: Upgrades from Debian 12 and Chapter 5: Issues to be aware of for trixie
- Debian News, Security support for Bookworm handed over to the LTS team (12 July 2026)
- Package versions checked against the Debian archive (
bind9-dnsutils,apt,ifupdown,network-manager) on 3 October 2026