Debian 9 (Stretch)
Debian 9 (Stretch)
The Debian 9 (Stretch) reached end of service life on Jul 1, 2022 — Debian no longer ships security patches or fixes for it. Our third-party support keeps it safe to run: 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance.
24/7 engineers own your Debian 9 (Stretch) incidents end to end.
Mitigation and patch-around guidance when the vendor no longer ships fixes.
Controls evidence and documentation that keep auditors satisfied.
Specifications
- product
- debian
- release
- 9
- product Label
- Debian
- release Label
- 9 (Stretch)
- codename
- Stretch
- lts
- latest Version
- 9.13
- release Date
- 2017-06-17
- maintained
- source Url
- https://endoflife.date/debian
Lifecycle Dates
- End of Service Life
- Jul 1, 2022
- Last OEM Support
- Jul 18, 2020
OEM vs. 3rd Party Support
See how third-party support compares to the vendor contract for Debian 9 (Stretch) — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| Break/Fix Support | Until EOSL | |
| 24/7 Monitoring | ||
| Vulnerability Scanning & Remediation | ||
| Managed Operations | ||
| Procedure & Configuration Review | ||
| Compliance & Audit Documentation | Limited | |
| Discounted Migration to Other Platforms |
Why Choose 3rd Party Support for Debian 9 (Stretch)?
Vulnerability Remediation
Scanning, mitigation and patch-around guidance for Debian 9 (Stretch) when the vendor no longer ships fixes.
Compliance Maintenance
Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.
24/7 Expert Support
Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.
Debian 9 (Stretch) Support: Frequently Asked Questions
Is the Debian 9 (Stretch) still supported?
Debian ended support for the Debian 9 (Stretch) on Jul 1, 2022 — no more patches or fixes from the vendor. Third-party support keeps it covered: our engineers manage issues, remediate vulnerabilities, and help you maintain compliance for as long as you run it.
When is the Debian 9 (Stretch) end of service life (EOSL) date?
Debian lists the end of service life for the Debian 9 (Stretch) as Jul 1, 2022.
Can I keep using the Debian 9 (Stretch) after its EOSL date?
Yes. EOSL means Debian stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.
How much does third-party support for the Debian 9 (Stretch) cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting Debian 9 (Stretch)
4008 published CVEs affect the Debian 9 (Stretch), including 2277 rated critical or high severity. Debian no longer ships security patches for this release — our engineers provide mitigation guidance, workarounds and hardening support.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2022-24884 | CRITICAL | 10.0 | May 6, 2022 | ecdsautils is a tiny collection of programs used for ECDSA (keygen, sign, verify). `ecdsa_verify_[prepare_]legacy()` does not check whether the signature values `r` and `s` are non-zero. A signature consisting only of zeroes is always considered valid, making it trivial to forge signatures. Requiring multiple signatures from different public keys does not mitigate the issue: `ecdsa_verify_list_legacy()` will accept an arbitrary number of such forged signatures. Both the `ecdsautil verify` CLI co |
| CVE-2021-44228 | CRITICAL | 10.0 | Dec 10, 2021 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along wit |
| CVE-2021-38503 | CRITICAL | 10.0 | Dec 8, 2021 | The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navigating the top-level frame. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3. |
| CVE-2018-18505 | CRITICAL | 10.0 | Feb 5, 2019 | An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and server parents during IPC process creation. This authentication is insufficient for channels created after the IPC process is started, leading to the authentication not being correctly applied to later channels. This could allow for a sandbox escape through IPC channels due to lack of message validation in the listener process. This vulnerability a |
| CVE-2018-14721 | CRITICAL | 10.0 | Jan 2, 2019 | FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization. |
| CVE-2017-16845 | CRITICAL | 10.0 | Nov 17, 2017 | hw/input/ps2.c in Qemu does not validate 'rptr' and 'count' values during guest migration, leading to out-of-bounds access. |
| CVE-2015-8104 | CRITICAL | 10.0 | Nov 16, 2015 | The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #DB (aka Debug) exceptions, related to svm.c. |
| CVE-2018-12892 | CRITICAL | 9.9 | Jul 2, 2018 | An issue was discovered in Xen 4.7 through 4.10.x. libxl fails to pass the readonly flag to qemu when setting up a SCSI disk, due to what was probably an erroneous merge conflict resolution. Malicious guest administrators or (in some situations) users may be able to write to supposedly read-only disk images. Only emulated SCSI disks (specified as "sd" in the libxl disk configuration, or an equivalent) are affected. IDE disks ("hd") are not affected (because attempts to make them readonly are rej |
| CVE-2022-31799 | CRITICAL | 9.8 | Jun 2, 2022 | Bottle before 0.12.20 mishandles errors during early request binding. |
| CVE-2022-1664 | CRITICAL | 9.8 | May 26, 2022 | Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversal vulnerability. When extracting untrusted source packages in v2 and v3 source package formats that include a debian.tar, the in-place extraction can lead to directory traversal situations on specially crafted orig.tar and debian.tar tarballs. |
| CVE-2022-29155 | CRITICAL | 9.8 | May 4, 2022 | In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL statement within an LDAP query. This can occur during an LDAP search operation when the search filter is processed, due to a lack of proper escaping. |
| CVE-2022-28044 | CRITICAL | 9.8 | Apr 15, 2022 | Irzip v0.640 was discovered to contain a heap memory corruption via the component lrzip.c:initialise_control. |
| CVE-2022-28346 | CRITICAL | 9.8 | Apr 12, 2022 | An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a crafted dictionary (with dictionary expansion) as the passed **kwargs. |
| CVE-2022-24786 | CRITICAL | 9.8 | Apr 6, 2022 | PJSIP is a free and open source multimedia communication library written in C. PJSIP versions 2.12 and prior do not parse incoming RTCP feedback RPSI (Reference Picture Selection Indication) packet, but any app that directly uses pjmedia_rtcp_fb_parse_rpsi() will be affected. A patch is available in the `master` branch of the `pjsip/pjproject` GitHub repository. There are currently no known workarounds. |
| CVE-2022-0547 | CRITICAL | 9.8 | Mar 18, 2022 | OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials. |
| CVE-2022-23943 | CRITICAL | 9.8 | Mar 14, 2022 | Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions. |
| CVE-2022-22720 | CRITICAL | 9.8 | Mar 14, 2022 | Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling |
| CVE-2022-26495 | CRITICAL | 9.8 | Mar 6, 2022 | In nbd-server in nbd before 3.24, there is an integer overflow with a resultant heap-based buffer overflow. A value of 0xffffffff in the name length field will cause a zero-sized buffer to be allocated for the name, resulting in a write to a dangling pointer. This issue exists for the NBD_OPT_INFO, NBD_OPT_GO, and NBD_OPT_EXPORT_NAME messages. |
| CVE-2022-0730 | CRITICAL | 9.8 | Mar 3, 2022 | Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types. |
| CVE-2021-3657 | CRITICAL | 9.8 | Feb 18, 2022 | A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (>=2GiB) IMAP literals, malicious or compromised IMAP servers, and hypothetically even external email senders, could cause several different buffer overflows, which could conceivably be exploited for remote code execution. |
Showing the 20 most severe of 4008 known CVEs.
Get Third Party Support