not_IO@lemmy.blahaj.zone to linuxmemes@lemmy.worldEnglish · 2 days agohttps://lists.debian.org/debian-security-announce/2026/msg00441.htmllemmy.blahaj.zoneimagemessage-square52linkfedilinkarrow-up1329arrow-down13file-text
arrow-up1326arrow-down1imagehttps://lists.debian.org/debian-security-announce/2026/msg00441.htmllemmy.blahaj.zonenot_IO@lemmy.blahaj.zone to linuxmemes@lemmy.worldEnglish · 2 days agomessage-square52linkfedilinkfile-text
minus-squareRestrictedAccount@lemmy.worldlinkfedilinkarrow-up10arrow-down1·2 days agoI saw this in the CISA announcement today. I was wondering if either: the project to port the kernel to rust Or people using AI to look for vulnerabilities Caused the huge list? (IBM had a ton too)
minus-squareOoops@feddit.orglinkfedilinkarrow-up22·2 days agoMore the fact that it’s Debian and they still support huge amounts of ancient stuff. There are year’s old ones in the list… alas, Debian still supports kernels like 5.10LTS. And backporting fixes doesn’t get easier over time.
minus-squaredgdft@lemmy.worldlinkfedilinkEnglisharrow-up11·2 days agoIt’s the latter; the kernel CVE report counts have gone through the roof in the past few years. No one is porting the whole kernel to rust (as part of the official project, at least).
I saw this in the CISA announcement today. I was wondering if either:
Caused the huge list?
(IBM had a ton too)
Given 1 isn’t true, it’s a rather easy guess
More the fact that it’s Debian and they still support huge amounts of ancient stuff. There are year’s old ones in the list… alas, Debian still supports kernels like 5.10LTS. And backporting fixes doesn’t get easier over time.
It’s the latter; the kernel CVE report counts have gone through the roof in the past few years.
No one is porting the whole kernel to rust (as part of the official project, at least).