Not really; the Linux kernel has had 8500 CVEs so far this year (according to this).
Most of them aren’t actually known to be definitely-exploitable security bugs, but some are. You can read more about how Linux issues CVEs from this post on Greg Kroah-Hartman’s website: Linux CVEs, more than you ever wanted to know (and/or watch one of his talks on the subject which is linked from there).
Yeah, just to add some context, you can detect potential buffer overruns in code by looking for patterns but just because you find potential buffer overruns doesn’t mean they are exploitable. The user needs to be able to inject not just code or parameters but also a return address that causes the injected code to run or triggers another function call with the injected parameters. With randomized code and stack addresses, this can be difficult or practically impossible, even if it’s easy to customize what bytes go into the overrun part of the buffer.
It’s like finding small parts of dangerous patterns but those small parts aren’t necessarily dangerous on their own and need more of the pattern to be an issue, but if you fix the small parts you find, you’re less likely run into those bigger patterns, so it’s worthwhile to fix the small patterns when they come up, but without fitting into a larger pattern, it wasn’t an actual security hole, just a potential one.
But still listing year’s old vulnerabilities that got fixed long ago because they are still supporting ancient stuff like 5.10LTS is Debian-specific.
The advisory this meme is about only relates to the 6.12 kernel in Debian 13 “trixie” (Debian’s current stable release), and 1,295 of these 1,313 CVEs are from 2026.
Linux 6.12 is the SLTS (“super long-term support”) release from 2024, so the Linux Foundation’s Civil Infrastructure Platform plans to continue backporting security fixes to it until 2035.
Debian stopped supporting Debian 11 “bullseye” (the one with a 5.10 kernel) in August, but that kernel is also an SLTS which CIP plans to support until 2031.
So, no, continuing support for these kernels is not something Debian-specific.
Debian problems I guess
Not really; the Linux kernel has had 8500 CVEs so far this year (according to this).
Most of them aren’t actually known to be definitely-exploitable security bugs, but some are. You can read more about how Linux issues CVEs from this post on Greg Kroah-Hartman’s website: Linux CVEs, more than you ever wanted to know (and/or watch one of his talks on the subject which is linked from there).
See also this article from July: Linux kernel team publishes 432 CVEs in two days: Sunday-to-Monday onslaught fuels speculation over AI-assisted bug reports.
Yeah, just to add some context, you can detect potential buffer overruns in code by looking for patterns but just because you find potential buffer overruns doesn’t mean they are exploitable. The user needs to be able to inject not just code or parameters but also a return address that causes the injected code to run or triggers another function call with the injected parameters. With randomized code and stack addresses, this can be difficult or practically impossible, even if it’s easy to customize what bytes go into the overrun part of the buffer.
It’s like finding small parts of dangerous patterns but those small parts aren’t necessarily dangerous on their own and need more of the pattern to be an issue, but if you fix the small parts you find, you’re less likely run into those bigger patterns, so it’s worthwhile to fix the small patterns when they come up, but without fitting into a larger pattern, it wasn’t an actual security hole, just a potential one.
They are not Debian-specific.
But still listing year’s old vulnerabilities that got fixed long ago because they are still supporting ancient stuff like 5.10LTS is Debian-specific.
The advisory this meme is about only relates to the 6.12 kernel in Debian 13 “trixie” (Debian’s current stable release), and 1,295 of these 1,313 CVEs are from 2026.
Linux 6.12 is the SLTS (“super long-term support”) release from 2024, so the Linux Foundation’s Civil Infrastructure Platform plans to continue backporting security fixes to it until 2035.
Debian stopped supporting Debian 11 “bullseye” (the one with a 5.10 kernel) in August, but that kernel is also an SLTS which CIP plans to support until 2031.
So, no, continuing support for these kernels is not something Debian-specific.
Here are the versions of linux-image-amd64 in Debian currently:
bullseye (oldoldstable) (kernel): Linux for 64-bit PCs (meta-package) 5.10.262-1 [security]: amd64 bookworm (oldstable) (kernel): Linux for 64-bit PCs (meta-package) 6.1.187-1 [security]: amd64 bookworm-backports (kernel): Linux for 64-bit PCs (meta-package) 6.12.95-1~bpo12+1: amd64 trixie (stable) (kernel): Linux for 64-bit PCs (meta-package) 6.12.111-1 [security]: amd64 trixie-backports (kernel): Linux for 64-bit PCs (meta-package) 7.1.13-1~bpo13+1: amd64 forky (testing) (kernel): Linux for 64-bit PCs (meta-package) 7.2.8-1: amd64 sid (unstable) (kernel): Linux for 64-bit PCs (meta-package) 7.2.8-1: amd64