Debian 11 Bullseye Is Now Officially Unsupported
Debian 11 “Bullseye” has reached the end of its support life. It no longer receives security updates from the Debian project, and any Bullseye system still in production is now accumulating unpatched vulnerabilities with no vendor fix coming.
Bullseye was released in August 2021, received three years of standard security support, then two further years under the LTS umbrella. That is a five-year lifecycle, which is generous by most standards and exactly what Debian promises.
What this actually means
There is no cliff-edge failure. Your Bullseye servers will boot tomorrow and the day after. The change is that the flow of security fixes has stopped, so the gap between “vulnerabilities that exist” and “vulnerabilities you have patched” now only widens.
For an internet-facing service, that is a countdown. For an isolated internal system, it is a slower problem but still a real one, because the next thing that compromises an internal network is usually something that reached it from outside.
The upgrade path
Debian supports upgrades one release at a time, so the sequence from Bullseye is 11 to 12 (Bookworm), then 12 to 13 (Trixie). Skipping a release is not supported and will produce a broken package state often enough that it is not worth attempting.
Before starting:
# know exactly what you have
cat /etc/debian_version
dpkg -l | grep -c '^ii'
# clear any half-configured packages first
sudo apt update && sudo apt full-upgrade
sudo dpkg --audit
An upgrade with unresolved package states is how a routine dist-upgrade becomes an evening. Our package and repository explainer covers what apt is doing underneath if the process is unfamiliar.
Take a snapshot or a full backup first. Our backup guide covers doing that properly, and this is the specific case it exists for: an upgrade you can roll back is a maintenance window, and an upgrade you cannot is a gamble.
If you cannot upgrade yet
Some systems genuinely cannot move on a short timeline, usually because of an application that was certified against a specific library version by a vendor who has since stopped answering email.
The realistic mitigations are containment rather than patching: put the host behind a firewall that permits only what it actually needs, remove its outbound internet access if the workload allows, and treat it as untrusted from the rest of the network’s perspective. Our firewall basics guide covers the mechanics.
Commercial extended support for Debian exists through third parties such as Freexian’s ELTS, which is a legitimate option for a fleet that needs more runway. It is not free, and it is a way to buy time rather than a substitute for a migration plan.
Context
The timing is a reasonable prompt to look at the wider picture. Debian 13 “Trixie” is the current stable release, now being deployed at CERN across 2,200 accelerator control systems, and Debian 12 remains supported.
If you have Bullseye anywhere, the question to answer this week is which of those two you are heading for, not whether you are.