Debian End of Life (EOL) Dates & Support Timeline
Complete end-of-life dates, support windows, and security status for all Debian versions. Data sourced from endoflife.date and official vendor documentation. Updated at every deploy.
| Version | Latest Release | Release Date | EOL Date | Days | Status |
|---|---|---|---|---|---|
| 1.1 | 1.1 | Jun 17, 1996 | Dec 12, 1996 | 10805 days past EOL | EOL |
| 1.2 | 1.2 | Dec 12, 1996 | Oct 23, 1997 | 10490 days past EOL | EOL |
| 1.3 | 1.3.1 r.6 | Jul 2, 1997 | Dec 8, 1998 | 10079 days past EOL | EOL |
| 2.0 | 2.0r5 | Jul 24, 1998 | Feb 15, 1999 | 10010 days past EOL | EOL |
| 2.1 | 2.1r5 | Mar 9, 1999 | Sep 30, 2000 | 9417 days past EOL | EOL |
| 2.2 | 2.2r7 | Aug 15, 2000 | Jun 30, 2003 | 8414 days past EOL | EOL |
| 3.0 | 3.0r6 | Jul 19, 2002 | Jun 30, 2006 | 7318 days past EOL | EOL |
| 3.1 | 3.1r8 | Jun 6, 2005 | Mar 31, 2008 | 6678 days past EOL | EOL |
| 4 | 4.0r9 | Apr 8, 2007 | Feb 15, 2010 | 5992 days past EOL | EOL |
| 5 | 5.0.10 | Feb 14, 2009 | Feb 6, 2012 | 5271 days past EOL | EOL |
| 6 | 6.0.10 | Feb 6, 2011 | May 31, 2014 | 4426 days past EOL | EOL |
| 7 | 7.11 | May 4, 2013 | Apr 25, 2016 | 3731 days past EOL | EOL |
| 8 | 8.11 | Apr 25, 2015 | Jun 17, 2018 | 2948 days past EOL | EOL |
| 9 | 9.13 | Jun 17, 2017 | Jul 18, 2020 | 2186 days past EOL | EOL |
| 10 | 10.13 | Jul 6, 2019 | Sep 10, 2022 | 1402 days past EOL | EOL |
| 11 | 11.11 | Aug 14, 2021 | Aug 14, 2024 | 698 days past EOL | EOL |
| 12 | 12.15 | Jun 10, 2023 | Jul 11, 2026 | 2 days past EOL | EOL |
| 13 | 13.6 | Aug 9, 2025 | Aug 9, 2028 | 758 days remaining | Active |
What does Debian end of life mean for your organization?
When a version of Debian reaches end of life, the maintainers stop issuing security patches. Vulnerabilities discovered after this date are publicly disclosed on the National Vulnerability Database, exploit code appears on GitHub, and your systems remain permanently exposed.
The CVE blind spot: Most vulnerability scanners check for known CVEs but do not flag the accumulation of unpatched vulnerabilities in EOL software. With a zero-day, nobody knows about the vulnerability. With EOL software, the vulnerability is public — listed, rated, and often weaponized — but no patch will ever exist. This is the most dangerous gap in enterprise security posture.
Organizations running EOL Debian should treat it as a vulnerability class in their risk register, apply compensating controls (network segmentation, enhanced monitoring, access restriction), and prioritize migration to a supported version.
Extended Support Options
If you cannot migrate immediately, extended support vendors provide continued security patches for EOL Debian versions. This is a bridge, not a permanent solution — plan your migration in parallel.
Debian has 17 versions past end of life — security patches have stopped, but CVE disclosures haven't. Tell us what you run and we'll match you with a vetted extended-support provider within 1 business day. Free, no obligation.
Get My Support Options →