Debian 12 patch

Hi

I have Debian machine os version 12 found that Bigfix only report 3 patches required but when I tried below command from machine itself found it required many patches

apt list --upgradable

Listing... Done

7zip/oldstable-security 22.01+really26.02+dfsg-0+deb12u1 amd64 [upgradable from: 22.01+really26.01+dfsg-0+deb12u1]

bind9-dnsutils/oldstable-security 1:9.18.49-1~deb12u2 amd64 [upgradable from: 1:9.18.49-1~deb12u1]

bind9-host/oldstable-security 1:9.18.49-1~deb12u2 amd64 [upgradable from: 1:9.18.49-1~deb12u1]

bind9-libs/oldstable-security 1:9.18.49-1~deb12u2 amd64 [upgradable from: 1:9.18.49-1~deb12u1]

ca-certificates/oldstable-security 20250419~deb12u1 all [upgradable from: 20230311+deb12u1]

firefox-esr/oldstable-security 140.14.0esr-1~deb12u1 amd64 [upgradable from: 140.13.0esr-1~deb12u1]

gsasl-common/oldstable-security 2.2.0-1+deb12u2 all [upgradable from: 2.2.0-1+deb12u1]

libaprutil1-dbd-sqlite3/oldstable-security 1.6.3-1+deb12u1 amd64 [upgradable from: 1.6.3-1]

libaprutil1-ldap/oldstable-security 1.6.3-1+deb12u1 amd64 [upgradable from: 1.6.3-1]

libaprutil1/oldstable-security 1.6.3-1+deb12u1 amd64 [upgradable from: 1.6.3-1]

libarchive13/oldstable-security 3.6.2-1+deb12u5 amd64 [upgradable from: 3.6.2-1+deb12u4]

libgsasl18/oldstable-security 2.2.0-1+deb12u2 amd64 [upgradable from: 2.2.0-1+deb12u1]

libnet-dns-perl/oldstable-security 1.36-1+deb12u1 all [upgradable from: 1.36-1]

libnss3/oldstable-security 2:3.87.1-1+deb12u4 amd64 [upgradable from: 2:3.87.1-1+deb12u3]

libpoppler-cpp0v5/oldstable-security 22.12.0-2+deb12u3 amd64 [upgradable from: 22.12.0-2+deb12u2]

libpoppler-glib8/oldstable-security 22.12.0-2+deb12u3 amd64 [upgradable from: 22.12.0-2+deb12u2]

libpoppler126/oldstable-security 22.12.0-2+deb12u3 amd64 [upgradable from: 22.12.0-2+deb12u2]

libpq5/oldstable-security 15.19-0+deb12u1 amd64 [upgradable from: 15.18-0+deb12u1]

libraw20/oldstable-security 0.20.2-2.1+deb12u2 amd64 [upgradable from: 0.20.2-2.1+deb12u1]

linux-image-amd64/oldstable-security 6.1.180-1 amd64 [upgradable from: 6.1.177-1]

linux-libc-dev/oldstable-security 6.1.180-1 amd64 [upgradable from: 6.1.177-1]

openjdk-17-jdk-headless/oldstable-security 17.0.20.1+1-1~deb12u1 amd64 [upgradable from: 17.0.20+8-1~deb12u1]

openjdk-17-jdk/oldstable-security 17.0.20.1+1-1~deb12u1 amd64 [upgradable from: 17.0.20+8-1~deb12u1]

openjdk-17-jre-headless/oldstable-security 17.0.20.1+1-1~deb12u1 amd64 [upgradable from: 17.0.20+8-1~deb12u1]

openjdk-17-jre/oldstable-security 17.0.20.1+1-1~deb12u1 amd64 [upgradable from: 17.0.20+8-1~deb12u1]

p7zip-full/oldstable-security 16.02+really26.02+dfsg-0+deb12u1 amd64 [upgradable from: 16.02+really26.01+dfsg-0+deb12u1]

p7zip/oldstable-security 16.02+really26.02+dfsg-0+deb12u1 amd64 [upgradable from: 16.02+really26.01+dfsg-0+deb12u1]

poppler-utils/oldstable-security 22.12.0-2+deb12u3 amd64 [upgradable from: 22.12.0-2+deb12u2]

python3-httplib2/oldstable-security 0.20.4-3+deb12u1 all [upgradable from: 0.20.4-3]

redis-server/oldstable-security 5:7.0.15-1~deb12u9 amd64 [upgradable from: 5:7.0.15-1~deb12u8]

redis-tools/oldstable-security 5:7.0.15-1~deb12u9 amd64 [upgradable from: 5:7.0.15-1~deb12u8]

unzip/oldstable-security 6.0-28+deb12u1 amd64 [upgradable from: 6.0-28]

xserver-common/oldstable-security 2:21.1.7-3+deb12u13 all [upgradable from: 2:21.1.7-3+deb12u12]

xserver-xephyr/oldstable-security 2:21.1.7-3+deb12u13 amd64 [upgradable from: 2:21.1.7-3+deb12u12]

xserver-xorg-core/oldstable-security 2:21.1.7-3+deb12u13 amd64 [upgradable from: 2:21.1.7-3+deb12u12]

xserver-xorg-legacy/oldstable-security 2:21.1.7-3+deb12u13 amd64 [upgradable from: 2:21.1.7-3+deb12u12]

So what may cause this issue

BR,

Mohamed

Hi there! It is actually very common to see a discrepancy between your local apt list and BigFix. BigFix relies on strict rules mapped to official Debian Security Advisories (DSAs). Based on your apt list --upgradable output, your Debian 12 machine is identifying these updates under the oldstable-security repository. Because Debian 13 has likely been released as the new "stable," Debian 12 has shifted to "oldstable."

Since Debian 12 has shifted to "oldstable," if your server's /etc/apt/sources.list is using the oldstable alias instead of explicitly stating bookworm, the BigFix agent might not recognize that the patches apply to your machine.

Additionally, BigFix filters out general bug fixes to focus strictly on major security vulnerabilities, and it often handles kernel updates separately to prevent unexpected reboots. It is also highly possible that your central BigFix Root Server just needs a quick sync with the external content servers to pull down the newest Fixlets for these very recent updates.

To resolve this, we recommend updating your repository sources to explicitly say bookworm, verifying that your BigFix server is fully synced with the "Patches for Debian 12" site, and then sending a "Force Refresh" to the endpoint via the BigFix console.

Thanks Satish will double check