-
-
Notifications
You must be signed in to change notification settings - Fork 237
Distribution Packages
Why Xpra recommends its official repositories instead of packages maintained by Linux distributions.
Warning
Xpra provides remote access and usually grants access to the user's home directory and applications. Do not run obsolete packages with known security issues. Install a supported version from the official repositories.
Apart from the obvious danger of running versions without any security updates, there are other problems with downstream packages:
- Unusable Xorg configurations in Debian variants.
- Broken builds, such as Fedora's invalid
startmode. - Invalid and unnecessary dependencies, including this Fedora example.
- Untested options or unsafe codecs enabled by default.
- Missing features, such as the HTML5 client in Debian packages.
- Downstream patches that cause regressionsâfor example, Debian ARM builds were unusable for years.
See the currently supported Xpra versions and download the official packages.
There is a very clear parallel to be made between security issues in vendor kernels and the lack of updates to downstream xpra packages - with the same consequences for users.
A great explanation of the Debian / Ubuntu packaging mess can be found here: âMatthew Garrett: There's more than one way to exploit the commons and also here: Debian Distribution-Specific Issues.
The problems with Ubuntu packages are severe enough to have their own wiki page.
Debian's hand waving about backports is rightfully ignored here.
These snapshots compare the Xpra release current at the time with versions shipped by common distributions. They are retained as historical evidence.
6.x comparison â August 2026
This table was generated on 2026-08-02, when 5.1.6 was the latest LTS version and 6.5.2 was the latest stable version. Ubuntu releases with standard support and Debian releases with regular or LTS support are included; paid extended support releases are not.
[!CAUTION] Versions older than 5.1.6 on the LTS branch or 6.5.1 on the stable branch are dangerous. They are vulnerable to serious known CVEs.
| Distribution | Variant | Version Shipped | Known Issues |
|---|---|---|---|
| Fedora | 43 and 44 | 6.5.1 | Good: only one stable update behind |
| Ubuntu | Jammy aka 22.04 | 3.1 | Unsupported upstream since August 2023; incompatible with Xpra 6.x |
| Ubuntu | Noble aka 24.04 | 3.1.5 | Unsupported upstream since August 2023; known to be broken with its Pillow version |
| Ubuntu | Resolute aka 26.04 | Not packaged | Not available from the distribution |
| Debian | Bullseye aka 11 | 3.0.13 | Unsupported upstream since October 2021, dangerous |
| Debian | Bookworm aka 12 | 3.1.3 | Unsupported upstream since August 2023; incompatible with Xpra 6.x |
| Debian | Trixie aka 13 | Not packaged | Removed from testing in April 2024 and absent from the release |
| Gentoo | Stable | 6.2.5-r1 | Unsupported upstream since April 2025 |
| Gentoo | Testing | 6.4.4 | Unsupported upstream since June 2026 |
| Arch | n/a | 6.4.4 | Unsupported upstream since June 2026; flagged out of date |
5.x comparison â May 2024
This table was generated on the 2024-05-24 when 5.0.8 was the latest LTS version available. (6.0.1 released the day before)
| Distribution | Variant | Version Shipped | Known Issues |
|---|---|---|---|
| Fedora | 39 and 40 | â5.0.6 | Not too old, but the packaging needs updating |
| Ubuntu | âFocal aka 20.04 | 3.0.6 | 4 years without any fixes, numerous serious issues, dangerous |
| Ubuntu | âJammy aka 22.04 | â3.1 | Outdated version from a dead branch, likely unusable anyway |
| Ubuntu | âNoble aka 24.04 | 3.1.5 | Outdated version from a dead branch, 1 year's worth of updates missing when released |
| Debian | âBuster | â2.4.3 | 5 years without any fixes, dangerous |
| Debian | âBullseye | â3.0.13 | 3.5 years without any fixes, dangerous |
| Debian | âBookworm | â3.0.13 | 3.5 years without any fixes, dangerous |
| Gentoo | âStable | â4.4.5 | Not a stable version, 1 year out of date |
| Gentoo | âTesting | â4.4.6 | 1 year out of date |
| âArch | n/a | â6.0 | Great: fully up to date |
3.0 comparison â January 2020
This table was generated on the 2020-01-17 when 3.0.5 was the latest LTS version available.
| Distribution | Variant | Version Shipped | Known Issues |
|---|---|---|---|
| Fedora | 30 and 31 | â3.0.3 | OK: 3.0.5 in testing, their packaging unmercifully conflicts with the packages from xpra.org, also contains invalid and unnecessary dependencies |
| Ubuntu | âXenial aka 16.04 | â0.15.8 | over 4 years without any fixes, many known bugs and security vulnerabilities - do not use, very dangerous, missing components, etc |
| Ubuntu | âBionic aka 18.04 | â2.1.3 | 2.5 years without any fixes, numerous serious issues, dangerous |
| Ubuntu | âEoan aka 19.10 | â2.4.3 | buggy, 14 months without any fixes |
| Debian | âBuster | â2.4.3 | buggy, 14 months without any fixes |
| Debian | âStretch | â0.17.6 | 3.5 years out of date, many known bugs and security vulnerabilities - do not use, very dangerous, missing components, etc |
| Gentoo | âStable | â2.2.2 | Dire: 2 years out of date! |
| Gentoo | âTesting | â3.0.2 | Missing some important fixes, dubious patches applied |
| âArch | n/a | â3.0.5 | Great: fully up to date |
1.0 comparison â March 2017
This table was generated on the 2017-03-18 when 1.0.4 was the latest LTS version available. (2.0 was released the day before)
| Distribution | Variant | Version Shipped | Known Issues |
|---|---|---|---|
| Fedora | 24 and 25 | â1.0 | missing critical updates |
| Ubuntu | âTrusty aka 14.04 | 0.12.3 | not a single fix applied in 3 years, dangerous |
| Ubuntu | Xenial aka 16.04 | â0.15.8 | 16 months without any fixes, based on a dead branch |
| Debian | âJessie | â0.14.10 | Awful: 2.5 years and 27 stable updates missing! Version no longer supported, includes known bugs, crashes and serious security vulnerabilities - dangerous! |
| Debian | âJessie-backports | 0.17.6 | Backports an EOL version!? |
| Debian | âStretch | 0.17.6 | EOL version, known bugs and security vulnerabilities - do not use |
| Gentoo | âStable â | 1.0.3 | Not too bad: 1 minor update behind |
| Gentoo | âTesting | 1.0.4 | Good: up to date! |
| âArch | n/a | 2.0 | Great: most up to date |
0.14 comparison â December 2015
This table was last updated 2015-12-28, when 0.15.10 was the latest version available. (0.14.33 for LTS branch).
| Distribution | Variant | Version Shipped | Known Issues |
|---|---|---|---|
| Fedora | 21 and 22 | â0.15.9 | Up to date (0.15.10 in "testing" queue) |
| Ubuntu | âPrecise aka 12.04 | 0.0.7.36 | Far too many to list - not a single bug fix applied in 4 years! |
| Ubuntu | âTrusty aka 13.04 | 0.12.3 | Far too many to list - not a single bug fix applied in 2 years, avoid |
| Ubuntu | âVivid aka 15.04 | 0.14.10 | Awful: 23 stable updates missing! version no longer supported, known bugs including crashes and vulnerabilities - avoid! |
| Debian | âSqueeze Backports | 0.3.11 | Fundamentally broken - do not use |
| Debian | âWheezy | 0.3.11 | Fundamentally broken - do not use |
| Debian | âWheezy-backports | 0.14.10 | Awful: 23 stable updates missing! version no longer supported, known bugs including crashes and vulnerabilities - avoid! |
| Debian | âJessie | 0.14.10 | Awful: 23 stable updates missing! version no longer supported, known bugs including crashes and vulnerabilities - avoid! |
| Debian | âJessie-backports | 0.16.3 | Not too bad |
| Gentoo | âStable | 0.15.6 | Not too bad: 4 minor updates behind |
| Gentoo | âTesting | â0.15.9 | Good: only one minor update behind |
| âArch | n/a | â0.15.9 | Good: only one minor update behind |
â Wiki home · Download official packages · Ubuntu package issues