[{"data":1,"prerenderedAt":29},["ShallowReactive",2],{"doc-en-debian-kernel-backports":3},{"path":4,"slug":5,"title":6,"description":7,"category":8,"subcategory":9,"icon":10,"date":11,"author":12,"order":13,"image":14,"tags":15,"keywords":20,"docGroup":16,"docGroupIcon":26,"link_fr":27,"bodyHtml":28},"\u002Fdocs\u002Fen\u002Fvps\u002Fvps-linux\u002Fdebian-kernel-backports","debian-kernel-backports","How to install a newer kernel on Debian via backports","Install a newer Debian kernel from the official backports repositories on your Winheberg VPS, with enabling, installing, checking and rolling back explained step by step.","vps","vps-linux","tabler:file-text","2026-07-24","Winheberg",33,"\u002Fstatics\u002Fimages\u002Fdocs\u002Fen\u002Fvps-linux\u002Fdebian-kernel-backports.webp",[16,17,18,8,19],"debian","kernel","backports","update",[21,22,23,24,25],"debian kernel backports","update debian kernel","bookworm-backports","install newer kernel vps","debian kernel update","tabler:brand-debian","\u002Fdocs\u002Fvps-linux\u002Fkernel-debian-backports","\u003Ch2>Context\u003C\u002Fh2>\n\u003Cp>You have a \u003Cstrong>Debian VPS\u003C\u002Fstrong> with Winheberg and you want to move to a more recent kernel than the one installed by default? The default Debian Stable kernel is deliberately very conservative, a guarantee of solid stability, but it can be too old for some uses, especially if you want the latest network optimisations, the newest hardware drivers, or the most recent features of the Linux kernel.\u003C\u002Fp>\n\u003Cp>This guide explains how to install a more recent kernel from the \u003Cstrong>official Debian backports repositories\u003C\u002Fstrong>, which offer more modern versions of the Linux kernel while still being maintained by the Debian team.\u003C\u002Fp>\n\u003Ch2>Why update your kernel?\u003C\u002Fh2>\n\u003Cp>The kernel is the core of your Linux system. Updating it brings several concrete benefits.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Better performance\u003C\u002Fstrong> on network, disk and CPU thanks to recent software optimisations, scheduler and TCP congestion algorithms\u003C\u002Fli>\n\u003Cli>\u003Cstrong>More recent virtio drivers\u003C\u002Fstrong>, virtio-net and virtio-blk\u002Fscsi, which bring new features and better performance on the guest side\u003C\u002Fli>\n\u003Cli>\u003Cstrong>New features\u003C\u002Fstrong> such as io_uring, fs-verity and recent BPF and eBPF capabilities\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Better support for containers\u003C\u002Fstrong>, Docker and Podman, and for nested virtualisation\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cdiv class=\"markdown-alert markdown-alert-important\">\u003Cspan class=\"alert-icon\">\u003Csvg xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\">\u003Cpath d=\"M12 22c5.523 0 10-4.477 10-10S17.523 2 12 2 2 6.477 2 12s4.477 10 10 10z\"\u002F>\u003Cpath d=\"M12 8v4\"\u002F>\u003Cpath d=\"M12 16h.01\"\u002F>\u003C\u002Fsvg>\u003C\u002Fspan>\u003Cdiv class=\"markdown-alert-body\">\u003Cp>Kernel security fixes arrive automatically through the usual updates with \u003Ccode>sudo apt update &amp;&amp; sudo apt full-upgrade\u003C\u002Fcode>. The \u003Ccode>bookworm-security\u003C\u002Fcode> repository, and its equivalent for other versions, continuously provides critical patches on the standard kernel. You therefore do not need to move to backports just for security.\u003C\u002Fp>\n\u003C\u002Fdiv>\u003C\u002Fdiv>\n\u003Cp>The real value of backports is moving to a more recent major version of the kernel, for example \u003Ccode>6.1\u003C\u002Fcode> to \u003Ccode>6.12\u003C\u002Fcode>, to get the new features and the latest optimisations, not for the security fixes that are already available on the standard kernel.\u003C\u002Fp>\n\u003Cdiv class=\"markdown-alert markdown-alert-note\">\u003Cspan class=\"alert-icon\">\u003Csvg xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\">\u003Ccircle cx=\"12\" cy=\"12\" r=\"10\"\u002F>\u003Cline x1=\"12\" y1=\"16\" x2=\"12\" y2=\"12\"\u002F>\u003Cline x1=\"12\" y1=\"8\" x2=\"12.01\" y2=\"8\"\u002F>\u003C\u002Fsvg>\u003C\u002Fspan>\u003Cdiv class=\"markdown-alert-body\">\u003Cp>The default Debian Stable kernel is deliberately conservative to guarantee maximum stability. Moving to a backports kernel is only useful if you have a real need for a more recent version, for example for new virtio features, advanced Docker compatibility, or modern kernel capabilities.\u003C\u002Fp>\n\u003C\u002Fdiv>\u003C\u002Fdiv>\n\u003Ch2>Prerequisites\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>A \u003Cstrong>Debian VPS\u003C\u002Fstrong>, version 11, 12 or 13, with Winheberg\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Root SSH access\u003C\u002Fstrong> or a user with \u003Ccode>sudo\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Mandatory\u003C\u002Fstrong>, a recent backup of your VPS before any operation\u003C\u002Fli>\n\u003Cli>A few minutes ahead of you, with a reboot planned at the end of the procedure\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cdiv class=\"markdown-alert markdown-alert-caution\">\u003Cspan class=\"alert-icon\">\u003Csvg xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\">\u003Ccircle cx=\"12\" cy=\"12\" r=\"10\"\u002F>\u003Cline x1=\"12\" y1=\"8\" x2=\"12\" y2=\"12\"\u002F>\u003Cline x1=\"12\" y1=\"16\" x2=\"12.01\" y2=\"16\"\u002F>\u003C\u002Fsvg>\u003C\u002Fspan>\u003Cdiv class=\"markdown-alert-body\">\u003Cp>Winheberg VPSes are based on Debian cloud images. If a new kernel prevents booting, you have a console available from your client area that displays the VPS boot screen. You can bring up the GRUB menu to reboot on a previous kernel, or switch to a rescue system via an ISO to repair your installation. Still keep a recent backup before touching the kernel, it remains your ultimate safety net if the repair fails.\u003C\u002Fp>\n\u003C\u002Fdiv>\u003C\u002Fdiv>\n\u003Cdiv class=\"markdown-alert markdown-alert-warning\">\u003Cspan class=\"alert-icon\">\u003Csvg xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\">\u003Cpath d=\"M10.29 3.86L1.82 18a2 2 0 0 0 1.71 3h16.94a2 2 0 0 0 1.71-3L13.71 3.86a2 2 0 0 0-3.42 0z\"\u002F>\u003Cline x1=\"12\" y1=\"9\" x2=\"12\" y2=\"13\"\u002F>\u003Cline x1=\"12\" y1=\"17\" x2=\"12.01\" y2=\"17\"\u002F>\u003C\u002Fsvg>\u003C\u002Fspan>\u003Cdiv class=\"markdown-alert-body\">\u003Cp>Any kernel change involves a server reboot. If you host a production service, website, game server or database, warn your users and schedule this operation during off-peak hours to limit the impact.\u003C\u002Fp>\n\u003C\u002Fdiv>\u003C\u002Fdiv>\n\u003Ch2>1. Check your current kernel version\u003C\u002Fh2>\n\u003Cp>First, check which kernel version currently runs on your VPS so you can compare after the operation.\u003C\u002Fp>\n\u003Cp>Connect to your VPS over SSH and run the following command.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">uname -r\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>You will get something like \u003Ccode>6.1.0-25-amd64\u003C\u002Fcode> or \u003Ccode>6.12.88-1~bpo12+1\u003C\u002Fcode>. This is the version currently running.\u003C\u002Fp>\n\u003Cp>To see the details of installed and available kernels, use \u003Ccode>apt policy\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">apt policy linux-image-amd64\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Here is a typical output on a Debian 12 (Bookworm) VPS.\u003C\u002Fp>\n\u003Cpre>\u003Ccode>linux-image-amd64:\n  Installed: 6.12.88-1~bpo12+1\n  Candidate: 6.12.88-1~bpo12+1\n  Version table:\n *** 6.12.88-1~bpo12+1 100\n        100 mirror+file:\u002Fetc\u002Fapt\u002Fmirrors\u002Fdebian.list bookworm-backports\u002Fmain amd64 Packages\n        100 \u002Fvar\u002Flib\u002Fdpkg\u002Fstatus\n     6.1.172-1 500\n        500 mirror+file:\u002Fetc\u002Fapt\u002Fmirrors\u002Fdebian-security.list bookworm-security\u002Fmain amd64 Packages\n     6.1.170-3 500\n        500 mirror+file:\u002Fetc\u002Fapt\u002Fmirrors\u002Fdebian.list bookworm\u002Fmain amd64 Packages\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>This example shows the following.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>The kernel \u003Cstrong>\u003Ccode>6.12.88-1~bpo12+1\u003C\u002Fcode>\u003C\u002Fstrong> is installed, coming from \u003Ccode>bookworm-backports\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>The kernel \u003Ccode>6.1.172-1\u003C\u002Fcode> is available from \u003Ccode>bookworm-security\u003C\u002Fcode>, the official security patches applied to the standard kernel\u003C\u002Fli>\n\u003Cli>The kernel \u003Ccode>6.1.170-3\u003C\u002Fcode> is available from the standard \u003Ccode>bookworm\u003C\u002Fcode> repository\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cdiv class=\"markdown-alert markdown-alert-note\">\u003Cspan class=\"alert-icon\">\u003Csvg xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\">\u003Ccircle cx=\"12\" cy=\"12\" r=\"10\"\u002F>\u003Cline x1=\"12\" y1=\"16\" x2=\"12\" y2=\"12\"\u002F>\u003Cline x1=\"12\" y1=\"8\" x2=\"12.01\" y2=\"8\"\u002F>\u003C\u002Fsvg>\u003C\u002Fspan>\u003Cdiv class=\"markdown-alert-body\">\u003Cp>The \u003Ccode>bookworm-security\u003C\u002Fcode> repository is crucial. It provides the official security fixes on the standard Debian kernel. As long as you regularly run \u003Ccode>sudo apt update &amp;&amp; sudo apt full-upgrade\u003C\u002Fcode>, your kernel receives these patches automatically, with no manual action on your part. This is why staying on the standard kernel is perfectly safe for most uses.\u003C\u002Fp>\n\u003C\u002Fdiv>\u003C\u002Fdiv>\n\u003Cdiv class=\"markdown-alert markdown-alert-tip\">\u003Cspan class=\"alert-icon\">\u003Csvg xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\">\u003Ccircle cx=\"12\" cy=\"12\" r=\"10\"\u002F>\u003Cpath d=\"M12 16v-4\"\u002F>\u003Cpath d=\"M12 8h.01\"\u002F>\u003C\u002Fsvg>\u003C\u002Fspan>\u003Cdiv class=\"markdown-alert-body\">\u003Cp>The \u003Ccode>bpo12+1\u003C\u002Fcode> suffix marks a kernel from the backports for Bookworm (Debian 12). This is what we aim to install for a more recent version.\u003C\u002Fp>\n\u003C\u002Fdiv>\u003C\u002Fdiv>\n\u003Ch2>2. Enable the backports repository\u003C\u002Fh2>\n\u003Cp>On Debian Stable, backports are not always enabled by default. You need to check for them and add them if necessary.\u003C\u002Fp>\n\u003Ch3>Identify your Debian version codename\u003C\u002Fh3>\n\u003Cp>First, find out which Debian version you use, because the backports repository name changes with the version.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">. \u002Fetc\u002Fos-release &amp;&amp; echo &quot;$VERSION_CODENAME&quot;\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>You will get \u003Ccode>bullseye\u003C\u002Fcode>, \u003Ccode>bookworm\u003C\u002Fcode> or \u003Ccode>trixie\u003C\u002Fcode>. Here is the mapping table.\u003C\u002Fp>\n\u003Ctable>\n\u003Cthead>\n\u003Ctr>\n\u003Cth>Debian version\u003C\u002Fth>\n\u003Cth>Codename\u003C\u002Fth>\n\u003Cth>Backports repository to use\u003C\u002Fth>\n\u003C\u002Ftr>\n\u003C\u002Fthead>\n\u003Ctbody>\u003Ctr>\n\u003Ctd>Debian 11\u003C\u002Ftd>\n\u003Ctd>\u003Ccode>bullseye\u003C\u002Fcode>\u003C\u002Ftd>\n\u003Ctd>\u003Ccode>bullseye-backports\u003C\u002Fcode>\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Debian 12\u003C\u002Ftd>\n\u003Ctd>\u003Ccode>bookworm\u003C\u002Fcode>\u003C\u002Ftd>\n\u003Ctd>\u003Ccode>bookworm-backports\u003C\u002Fcode>\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Debian 13\u003C\u002Ftd>\n\u003Ctd>\u003Ccode>trixie\u003C\u002Fcode>\u003C\u002Ftd>\n\u003Ctd>\u003Ccode>trixie-backports\u003C\u002Fcode>\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003C\u002Ftbody>\u003C\u002Ftable>\n\u003Cdiv class=\"markdown-alert markdown-alert-important\">\u003Cspan class=\"alert-icon\">\u003Csvg xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\">\u003Cpath d=\"M12 22c5.523 0 10-4.477 10-10S17.523 2 12 2 2 6.477 2 12s4.477 10 10 10z\"\u002F>\u003Cpath d=\"M12 8v4\"\u002F>\u003Cpath d=\"M12 16h.01\"\u002F>\u003C\u002Fsvg>\u003C\u002Fspan>\u003Cdiv class=\"markdown-alert-body\">\u003Cp>Always use the codename matching your installed version. Mixing a backports repository from another version can break your system. If you are on Debian 11 Bullseye, use \u003Ccode>bullseye-backports\u003C\u002Fcode>, on Debian 12 Bookworm use \u003Ccode>bookworm-backports\u003C\u002Fcode>, and so on.\u003C\u002Fp>\n\u003C\u002Fdiv>\u003C\u002Fdiv>\n\u003Cdiv class=\"markdown-alert markdown-alert-warning\">\u003Cspan class=\"alert-icon\">\u003Csvg xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\">\u003Cpath d=\"M10.29 3.86L1.82 18a2 2 0 0 0 1.71 3h16.94a2 2 0 0 0 1.71-3L13.71 3.86a2 2 0 0 0-3.42 0z\"\u002F>\u003Cline x1=\"12\" y1=\"9\" x2=\"12\" y2=\"13\"\u002F>\u003Cline x1=\"12\" y1=\"17\" x2=\"12.01\" y2=\"17\"\u002F>\u003C\u002Fsvg>\u003C\u002Fspan>\u003Cdiv class=\"markdown-alert-body\">\u003Cp>If you are on Debian 11 Bullseye, note that this version moved to the end of standard support in August 2024 and is now maintained only by the LTS project until mid-2026. For a production VPS, seriously consider a migration to Debian 12 or 13 rather than a simple kernel update.\u003C\u002Fp>\n\u003C\u002Fdiv>\u003C\u002Fdiv>\n\u003Ch3>Check whether backports are already enabled\u003C\u002Fh3>\n\u003Cp>Good news for Winheberg clients, our Debian VPSes, 12 and 13, ship with backports already enabled in the new DEB822 format. Check with the following command.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">grep -r &quot;backports&quot; \u002Fetc\u002Fapt\u002F\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>If you see a line like this one in \u003Ccode>\u002Fetc\u002Fapt\u002Fsources.list.d\u002Fdebian.sources\u003C\u002Fcode>, you are already set.\u003C\u002Fp>\n\u003Cpre>\u003Ccode>Suites: bookworm bookworm-updates bookworm-backports\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>The suites are adapted to your version, for example \u003Ccode>trixie trixie-updates trixie-backports\u003C\u002Fcode> on Debian 13. In that case, go straight to step 3, backports are enabled and you can install the kernel right away.\u003C\u002Fp>\n\u003Ch3>Add backports manually, if needed\u003C\u002Fh3>\n\u003Cp>If the command above returns nothing, or if you only see the standard repositories without \u003Ccode>-backports\u003C\u002Fcode>, you need to add the repository manually.\u003C\u002Fp>\n\u003Cp>For \u003Cstrong>Debian 11 (Bullseye)\u003C\u002Fstrong>, create a dedicated file.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">echo &quot;deb http:\u002F\u002Fdeb.debian.org\u002Fdebian bullseye-backports main contrib non-free&quot; | sudo tee \u002Fetc\u002Fapt\u002Fsources.list.d\u002Fbackports.list\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>For \u003Cstrong>Debian 12 (Bookworm)\u003C\u002Fstrong>, run the following command.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">echo &quot;deb http:\u002F\u002Fdeb.debian.org\u002Fdebian bookworm-backports main contrib non-free non-free-firmware&quot; | sudo tee \u002Fetc\u002Fapt\u002Fsources.list.d\u002Fbackports.list\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>For \u003Cstrong>Debian 13 (Trixie)\u003C\u002Fstrong>, run this one instead.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">echo &quot;deb http:\u002F\u002Fdeb.debian.org\u002Fdebian trixie-backports main contrib non-free non-free-firmware&quot; | sudo tee \u002Fetc\u002Fapt\u002Fsources.list.d\u002Fbackports.list\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Then in every case, refresh the list of available packages.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">sudo apt update\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cdiv class=\"markdown-alert markdown-alert-note\">\u003Cspan class=\"alert-icon\">\u003Csvg xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\">\u003Ccircle cx=\"12\" cy=\"12\" r=\"10\"\u002F>\u003Cline x1=\"12\" y1=\"16\" x2=\"12\" y2=\"12\"\u002F>\u003Cline x1=\"12\" y1=\"8\" x2=\"12.01\" y2=\"8\"\u002F>\u003C\u002Fsvg>\u003C\u002Fspan>\u003Cdiv class=\"markdown-alert-body\">\u003Cp>If you prefer to edit the DEB822 format (\u003Ccode>\u002Fetc\u002Fapt\u002Fsources.list.d\u002Fdebian.sources\u003C\u002Fcode>) rather than adding a classic \u003Ccode>.list\u003C\u002Fcode> file, open the file with your editor and add \u003Ccode>bookworm-backports\u003C\u002Fcode>, or its equivalent, to the \u003Ccode>Suites:\u003C\u002Fcode> line. Both formats work, but do not duplicate the same information in both places.\u003C\u002Fp>\n\u003C\u002Fdiv>\u003C\u002Fdiv>\n\u003Ch2>3. Check the availability of a more recent kernel\u003C\u002Fh2>\n\u003Cp>Now that backports are enabled, check which kernels are available.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">apt policy linux-image-amd64\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>You should now see an extra line pointing to the backports repository, \u003Ccode>bullseye-backports\u003C\u002Fcode>, \u003Ccode>bookworm-backports\u003C\u002Fcode> or \u003Ccode>trixie-backports\u003C\u002Fcode> depending on your version, with a version number more recent than the one currently installed.\u003C\u002Fp>\n\u003Cdiv class=\"markdown-alert markdown-alert-tip\">\u003Cspan class=\"alert-icon\">\u003Csvg xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\">\u003Ccircle cx=\"12\" cy=\"12\" r=\"10\"\u002F>\u003Cpath d=\"M12 16v-4\"\u002F>\u003Cpath d=\"M12 8h.01\"\u002F>\u003C\u002Fsvg>\u003C\u002Fspan>\u003Cdiv class=\"markdown-alert-body\">\u003Cp>To see all the kernels available in backports, use the following command.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">apt list -a linux-image-amd64\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003C\u002Fdiv>\u003C\u002Fdiv>\n\u003Ch2>4. Install the kernel from backports\u003C\u002Fh2>\n\u003Cp>Here is the key command to install the kernel from backports. Adapt the \u003Ccode>-t\u003C\u002Fcode> option to your Debian version.\u003C\u002Fp>\n\u003Cp>For \u003Cstrong>Debian 11 (Bullseye)\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">sudo apt install -t bullseye-backports linux-image-amd64\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>For \u003Cstrong>Debian 12 (Bookworm)\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">sudo apt install -t bookworm-backports linux-image-amd64\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>For \u003Cstrong>Debian 13 (Trixie)\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">sudo apt install -t trixie-backports linux-image-amd64\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>The \u003Ccode>-t &lt;backports-name&gt;\u003C\u002Fcode> option tells APT to force the installation from the backports repository, not from the standard one.\u003C\u002Fp>\n\u003Cp>APT will show the list of packages to install, including dependencies such as the kernel headers. Confirm with \u003Ccode>Y\u003C\u002Fcode> to start the installation.\u003C\u002Fp>\n\u003Cdiv class=\"markdown-alert markdown-alert-important\">\u003Cspan class=\"alert-icon\">\u003Csvg xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\">\u003Cpath d=\"M12 22c5.523 0 10-4.477 10-10S17.523 2 12 2 2 6.477 2 12s4.477 10 10 10z\"\u002F>\u003Cpath d=\"M12 8v4\"\u002F>\u003Cpath d=\"M12 16h.01\"\u002F>\u003C\u002Fsvg>\u003C\u002Fspan>\u003Cdiv class=\"markdown-alert-body\">\u003Cp>APT downloads and installs the new kernel alongside the old one. Your current kernel stays functional until the reboot. If something goes wrong, you can still reboot on the old one.\u003C\u002Fp>\n\u003C\u002Fdiv>\u003C\u002Fdiv>\n\u003Ch3>Install the headers too, optional but recommended\u003C\u002Fh3>\n\u003Cp>If you plan to compile modules, third-party drivers, ZFS or a custom WireGuard, install the matching headers too.\u003C\u002Fp>\n\u003Cp>For \u003Cstrong>Debian 11 (Bullseye)\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">sudo apt install -t bullseye-backports linux-headers-amd64\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>For \u003Cstrong>Debian 12 (Bookworm)\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">sudo apt install -t bookworm-backports linux-headers-amd64\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>For \u003Cstrong>Debian 13 (Trixie)\u003C\u002Fstrong>.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">sudo apt install -t trixie-backports linux-headers-amd64\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Ch2>5. Check the installation\u003C\u002Fh2>\n\u003Cp>Once the installation is finished, check that the new kernel is present.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">dpkg -l | grep linux-image\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>You should see at least two entries.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Your old kernel, still installed for safety\u003C\u002Fli>\n\u003Cli>The new kernel from backports\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>You can also check the contents of \u003Ccode>\u002Fboot\u002F\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">ls -lh \u002Fboot\u002Fvmlinuz-*\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>The new kernel should be listed with its recent version.\u003C\u002Fp>\n\u003Ch2>6. Reboot your VPS\u003C\u002Fh2>\n\u003Cp>For the new kernel to load, you need to reboot your VPS.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">sudo reboot\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cdiv class=\"markdown-alert markdown-alert-warning\">\u003Cspan class=\"alert-icon\">\u003Csvg xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\">\u003Cpath d=\"M10.29 3.86L1.82 18a2 2 0 0 0 1.71 3h16.94a2 2 0 0 0 1.71-3L13.71 3.86a2 2 0 0 0-3.42 0z\"\u002F>\u003Cline x1=\"12\" y1=\"9\" x2=\"12\" y2=\"13\"\u002F>\u003Cline x1=\"12\" y1=\"17\" x2=\"12.01\" y2=\"17\"\u002F>\u003C\u002Fsvg>\u003C\u002Fspan>\u003Cdiv class=\"markdown-alert-body\">\u003Cp>The SSH connection will drop during the reboot. Wait 30 seconds to 1 minute before trying to reconnect.\u003C\u002Fp>\n\u003C\u002Fdiv>\u003C\u002Fdiv>\n\u003Ch2>7. Check that the new kernel is loaded\u003C\u002Fh2>\n\u003Cp>Reconnect over SSH and check the active version.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">uname -r\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>You should now see the backports kernel version, for example \u003Ccode>6.12.88-1~bpo12+1\u003C\u002Fcode> or newer. Also check with the following command.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">uname -a\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>This gives a full output including the kernel build date.\u003C\u002Fp>\n\u003Cdiv class=\"markdown-alert markdown-alert-tip\">\u003Cspan class=\"alert-icon\">\u003Csvg xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\">\u003Ccircle cx=\"12\" cy=\"12\" r=\"10\"\u002F>\u003Cpath d=\"M12 16v-4\"\u002F>\u003Cpath d=\"M12 8h.01\"\u002F>\u003C\u002Fsvg>\u003C\u002Fspan>\u003Cdiv class=\"markdown-alert-body\">\u003Cp>If the version shown is still the old one, this usually means the reboot has not happened yet or the latest kernel was not selected at boot. Refer to the troubleshooting section below.\u003C\u002Fp>\n\u003C\u002Fdiv>\u003C\u002Fdiv>\n\u003Ch2>Troubleshooting\u003C\u002Fh2>\n\u003Ch3>❌ The server does not reboot after the update\u003C\u002Fh3>\n\u003Cp>This is rare with official backports kernels but possible, and it is the most critical scenario. You have several options.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Open your VPS console from your client area, it displays the boot screen. Bring up the GRUB menu at boot and select a previous kernel to reboot on the old kernel still installed\u003C\u002Fli>\n\u003Cli>If booting remains impossible, switch to a rescue system via an ISO from the console, then mount your disk to remove the faulty kernel or regenerate the boot configuration\u003C\u002Fli>\n\u003Cli>As a last resort, restoring a backup made before the operation brings the VPS back\u003C\u002Fli>\n\u003Cli>Contact our support at any time if you have a doubt, we can guide you through the console, the rescue system or the restore\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cdiv class=\"markdown-alert markdown-alert-tip\">\u003Cspan class=\"alert-icon\">\u003Csvg xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\">\u003Ccircle cx=\"12\" cy=\"12\" r=\"10\"\u002F>\u003Cpath d=\"M12 16v-4\"\u002F>\u003Cpath d=\"M12 8h.01\"\u002F>\u003C\u002Fsvg>\u003C\u002Fspan>\u003Cdiv class=\"markdown-alert-body\">\u003Cp>A backup made before the operation remains your best insurance if everything else fails.\u003C\u002Fp>\n\u003C\u002Fdiv>\u003C\u002Fdiv>\n\u003Ch3>❌ \u003Ccode>uname -r\u003C\u002Fcode> still shows the old version after reboot\u003C\u002Fh3>\n\u003Cp>If the reboot went fine but the kernel has not changed.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Check that the new kernel is indeed in \u003Ccode>\u002Fboot\u002F\u003C\u002Fcode>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cpre>\u003Ccode class=\"language-bash\">ls -lh \u002Fboot\u002Fvmlinuz-* \u002Fboot\u002Finitrd.img-*\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cul>\n\u003Cli>Check which kernels are installed on the system\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cpre>\u003Ccode class=\"language-bash\">dpkg -l | grep linux-image\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cul>\n\u003Cli>Try regenerating the boot configuration and reboot again\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cpre>\u003Ccode class=\"language-bash\">sudo update-grub\nsudo reboot\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cul>\n\u003Cli>If the problem persists, it is likely tied to the cloud image bootloader, contact our support\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>❌ A kernel module no longer loads, ZFS or a third-party module\u003C\u002Fh3>\n\u003Cp>Third-party modules (DKMS) you installed yourself, such as ZFS, must be recompiled for the new kernel version.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Reinstall the headers for the active kernel, adapting \u003Ccode>bullseye-backports\u003C\u002Fcode>, \u003Ccode>bookworm-backports\u003C\u002Fcode> or \u003Ccode>trixie-backports\u003C\u002Fcode> to your version\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cpre>\u003Ccode class=\"language-bash\">sudo apt install -t bookworm-backports linux-headers-amd64\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cul>\n\u003Cli>Recompile the DKMS modules for the new kernel\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cpre>\u003Ccode class=\"language-bash\">sudo dkms autoinstall -k $(uname -r)\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cul>\n\u003Cli>If a specific module still causes trouble, reinstall its DKMS package, for example \u003Ccode>sudo apt install --reinstall zfs-dkms\u003C\u002Fcode>, to force its rebuild\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>❌ I installed the wrong kernel, how do I go back to the old one?\u003C\u002Fh3>\n\u003Cp>No panic, the old kernel is still installed on your VPS and remains usable.\u003C\u002Fp>\n\u003Cp>While the server is still reachable, you have not rebooted yet or the new kernel works but does not suit you, simply remove the backports kernel.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">sudo apt remove linux-image-6.12.88-1~bpo12+1\nsudo reboot\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Adapt the version to your case. APT automatically regenerates the boot configuration and the system reboots on the old kernel still installed.\u003C\u002Fp>\n\u003Cdiv class=\"markdown-alert markdown-alert-important\">\u003Cspan class=\"alert-icon\">\u003Csvg xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\">\u003Cpath d=\"M12 22c5.523 0 10-4.477 10-10S17.523 2 12 2 2 6.477 2 12s4.477 10 10 10z\"\u002F>\u003Cpath d=\"M12 8v4\"\u002F>\u003Cpath d=\"M12 16h.01\"\u002F>\u003C\u002Fsvg>\u003C\u002Fspan>\u003Cdiv class=\"markdown-alert-body\">\u003Cp>Removing this specific kernel is not enough to go back for good. The \u003Ccode>linux-image-amd64\u003C\u002Fcode> metapackage stays pointed at backports, so a future \u003Ccode>sudo apt full-upgrade\u003C\u002Fcode> may reinstall a backports kernel. To stay permanently on the standard kernel, reinstall the metapackage from the standard repository, for example \u003Ccode>sudo apt install linux-image-amd64\u002Fbookworm\u003C\u002Fcode>, adapting the codename, or set up APT pinning giving a lower priority to backports.\u003C\u002Fp>\n\u003C\u002Fdiv>\u003C\u002Fdiv>\n\u003Cdiv class=\"markdown-alert markdown-alert-caution\">\u003Cspan class=\"alert-icon\">\u003Csvg xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\">\u003Ccircle cx=\"12\" cy=\"12\" r=\"10\"\u002F>\u003Cline x1=\"12\" y1=\"8\" x2=\"12\" y2=\"12\"\u002F>\u003Cline x1=\"12\" y1=\"16\" x2=\"12.01\" y2=\"16\"\u002F>\u003C\u002Fsvg>\u003C\u002Fspan>\u003Cdiv class=\"markdown-alert-body\">\u003Cp>If your VPS no longer reboots after installing the new kernel, open the console from your client area to bring up the GRUB menu and reboot on a previous kernel, or switch to a rescue system via an ISO to repair. A backup made before the operation remains the fallback if the repair fails.\u003C\u002Fp>\n\u003C\u002Fdiv>\u003C\u002Fdiv>\n\u003Ch2>Best practices\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Cstrong>Strongly recommended, make a backup\u003C\u002Fstrong> of your VPS, for example a full dump via \u003Ccode>tar\u003C\u002Fcode>, \u003Ccode>rsync\u003C\u002Fcode> or a remote backup tool, before touching the kernel, it is your ultimate safety net if rescue is not enough\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Test first on a spare VPS\u003C\u002Fstrong> if you have a critical production environment\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Read the kernel release notes\u003C\u002Fstrong> on \u003Ccode>kernel.org\u003C\u002Fcode> or the Debian backports announcements before updating\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Do not remove the old kernel\u003C\u002Fstrong> right away, keep it for a few days so you can go back if there is a problem\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Watch the logs\u003C\u002Fstrong> after the first reboot, \u003Ccode>dmesg\u003C\u002Fcode> and \u003Ccode>journalctl -b\u003C\u002Fcode>, to catch any warnings\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Update the backports kernel regularly\u003C\u002Fstrong>, like any other package, with \u003Ccode>sudo apt update &amp;&amp; sudo apt full-upgrade\u003C\u002Fcode>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Do not mix\u003C\u002Fstrong> backports packages with the standard system unless you have a specific need\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2>Need help?\u003C\u002Fh2>\n\u003Cp>If your server does not reboot after a kernel update, or if you have any doubt about the procedure, our team is available. Open a ticket in the \u003Cstrong>Technical\u003C\u002Fstrong> department from your client area, fill the \u003Cstrong>Produit lié\u003C\u002Fstrong> field with the VPS concerned, and we can guide you through the console, the rescue system or restoring a backup depending on your situation.\u003C\u002Fp>\n\u003Cp>Your Debian VPS now runs on a recent kernel, ready to make the most of the latest Linux features 🐧\u003C\u002Fp>\n",1788993144088]