• Ooops@feddit.org
      link
      fedilink
      arrow-up
      0
      ·
      1 day ago

      But still listing year’s old vulnerabilities that got fixed long ago because they are still supporting ancient stuff like 5.10LTS is Debian-specific.

      • Arthur Besse@lemmy.mlOP
        link
        fedilink
        English
        arrow-up
        0
        ·
        1 day ago

        But still listing year’s old vulnerabilities that got fixed long ago because they are still supporting ancient stuff like 5.10LTS is Debian-specific.

        The advisory this meme is about only relates to the 6.12 kernel in Debian 13 “trixie” (Debian’s current stable release), and 1,295 of these 1,313 CVEs are from 2026.

        Linux 6.12 is the SLTS (“super long-term support”) release from 2024, so the Linux Foundation’s Civil Infrastructure Platform plans to continue backporting security fixes to it until 2035.

        Debian stopped supporting Debian 11 “bullseye” (the one with a 5.10 kernel) in August, but that kernel is also an SLTS which CIP plans to support until 2031.

        So, no, continuing support for these kernels is not something Debian-specific.

        Here are the versions of linux-image-amd64 in Debian currently:

            bullseye (oldoldstable) (kernel): Linux for 64-bit PCs (meta-package)
            5.10.262-1 [security]: amd64
            bookworm (oldstable) (kernel): Linux for 64-bit PCs (meta-package)
            6.1.187-1 [security]: amd64
            bookworm-backports (kernel): Linux for 64-bit PCs (meta-package)
            6.12.95-1~bpo12+1: amd64
            trixie (stable) (kernel): Linux for 64-bit PCs (meta-package)
            6.12.111-1 [security]: amd64
            trixie-backports (kernel): Linux for 64-bit PCs (meta-package)
            7.1.13-1~bpo13+1: amd64
            forky (testing) (kernel): Linux for 64-bit PCs (meta-package)
            7.2.8-1: amd64
            sid (unstable) (kernel): Linux for 64-bit PCs (meta-package)
            7.2.8-1: amd64