cat looks inside meme template: DSA 6528-1: "Several vulnerabilities have been discovered in the Linux kernel" / looks inside / 1,313 CVEs

all 34 comments

sorted by: hot top controversial new old
[–] 1 point 28 minutes ago

It took me a while to scroll through the list of CVEs. Clearly, a whole new meaning for the word "few" that I was unaware of.

  • source
  • [–] 3 points 1 hour ago (1 child)

    All bugs are treated as CVEs

  • source
  • hideshow 1 child comment
  • [–] 35 points 4 hours ago

    Hmm yes "vulnerabilities".

    My personal highlight: https://nvd.nist.gov/vuln/detail/cve-2026-43073

    Rename misleadingly named '__copy_user_nocache()' function. This function was a masterclass in bad naming, for various historical reasons. It claimed to be a non-cached user copy. It is literally neither of those things.

    Credits: https://lemmy.world/comment/26110292

  • source
  • [–] 15 points 5 hours ago (4 children)

    1,313

    Less than one and a half? Not a big deal.

  • source
  • hideshow 4 child comments
  • [–] 3 points 2 hours ago (3 children)

    most countries (i think) use ',' for separating every 3 numbers instead of '.', which is used for separating decimals from whole numbers

  • source
  • parent
  • hideshow 3 child comments
  • [–] 10 points 2 hours ago

    Pretty sure the person you responded to knows that and is joking, since you can hardly have a fraction of a CVE. Germany (where their instance is hosted) uses comma for decimal separators, so that joke is pretty close at hand.

  • source
  • parent
  • [–] 2 points 2 hours ago* (1 child)

    Actually I am sure otherwise. I believe comma is more widespread per country (dot might be more widespread by populace due to China, though)

  • source
  • parent
  • hideshow 1 child comment
  • [–] [S] 1 point 1 hour ago* (last edited 1 hour ago)

    I believe comma is more widespread per country

    it looks like you might be right... I'm surprised to learn that https://en.wikipedia.org/wiki/Decimal_separator#Conventions_worldwide lists 83 countries who use comma as decimal separator, and only 59 who use dot (and presumably the thousands separator is usually the opposite of the decimal separator). However there are enough countries which aren't on either list that it isn't entirely clear from that page which convention is actually used in more countries.

    Also, it's much more complicated than the . vs , binary... among other oddities:

    • Historically, in Germany and Austria, thousands separators were occasionally denoted by alternating uses of commas and points, e.g. "1.234,567.890,12" (or "1.234,567.890Β·12" in Austria-Hungary and Austria prior to 1938) for "eine Milliarde 234 Millionen ...", but this is not seen today and contemporary German readers would require an explanation to understand it.
    • In Switzerland, there are two styles. Currency values use an apostrophe (') as a thousands separator along with a dot (.) as the decimal separator, like "1'234'567.89". For other values, the SI-style "1 234 567,89" is used, with a comma (,) as the decimal separator. The apostrophe is also the most common thousands separator for non-currency values, like "1'234'567,89".
  • source
  • parent
  • Honestly, great! More bugs found, more bugs fixed, better system for everyone.

  • source
  • [–] 68 points 9 hours ago (6 children)

    But how many of those are actual problems though?

  • source
  • hideshow 6 child comments
  • [–] 78 points 8 hours ago (3 children)

    To add, pretty much any kernel bug gets a CVE because everything wrong in the kernel could theoretically be abused.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 6 points 6 hours ago (5 children)

    If the PS5 is based off of Linux, and some of these vulnerabilities tested, don't impact the PS5 in any way, does that mean technically Sony could get sued for not recontributing code back to the Linux projects? I mean, it means they fixed the issues on the PS5 but didn't contribute it back right?

  • source
  • hideshow 5 child comments
  • [–] 4 points 3 hours ago

    vulnerabilities tested, don't impact the PS5 in any way, does that mean technically Sony could get sued for not recontributing code back to the Linux projects?

    No.

    Let's assume someone ships the Linux kernel in a device and the kernel has a vulnerability in some obscure subsystem (e.g. AFS) that is never used by the device. The device will not be affected by this vulnerability because the code can't be reached.

  • source
  • parent
  • [–] [S] 9 points 5 hours ago* (last edited 5 hours ago) (1 child)

    If the PS5 is based off of Linux

    I don't think it is though? After a few seconds searching I don't see anything conclusive but PS4's OS was based on FreeBSD so I would guess PS5's probably is also. (I see that if you have a PS5 with old enough firmware you can put Linux on it yourself...)

    Sony does have some experience shipping Linux-based products though (probably first with Linux for PS2 in 2002, and more recently various android devices) and surely knows how to comply with the GPL.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 22 points 8 hours ago

    Israel and the NSA must be sad

  • source
  • [–] 5 points 6 hours ago (3 children)
  • [–] 3 points 6 hours ago (2 children)
  • [–] 17 points 9 hours ago (4 children)

    For the stable distribution (trixie), these problems have been fixed in version 6.12.111-1.

    Debian problems I guess

  • source
  • hideshow 4 child comments
  • [–] [S] 23 points 8 hours ago* (last edited 8 hours ago)

    Debian problems I guess

    Not really; the Linux kernel has had 8500 CVEs so far this year (according to this).

    Most of them aren't actually known to be definitely-exploitable security bugs, but some are. You can read more about how Linux issues CVEs from this post on Greg Kroah-Hartman's website: Linux CVEs, more than you ever wanted to know (and/or watch one of his talks on the subject which is linked from there).

    See also this article from July: Linux kernel team publishes 432 CVEs in two days: Sunday-to-Monday onslaught fuels speculation over AI-assisted bug reports.

  • source
  • parent
  • [–] 11 points 9 hours ago (2 children)

    They are not Debian-specific.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 4 points 7 hours ago (1 child)

    But still listing year's old vulnerabilities that got fixed long ago because they are still supporting ancient stuff like 5.10LTS is Debian-specific.

  • source
  • parent
  • hideshow 1 child comment
  • [–] [S] 9 points 6 hours ago*

    But still listing year’s old vulnerabilities that got fixed long ago because they are still supporting ancient stuff like 5.10LTS is Debian-specific.

    The advisory this meme is about only relates to the 6.12 kernel in Debian 13 "trixie" (Debian's current stable release), and 1,295 of these 1,313 CVEs are from 2026.

    Linux 6.12 is the SLTS ("super long-term support") release from 2024, so the Linux Foundation's Civil Infrastructure Platform plans to continue backporting security fixes to it until 2035.

    Debian stopped supporting Debian 11 "bullseye" (the one with a 5.10 kernel) in August, but that kernel is also an SLTS which CIP plans to support until 2031.

    So, no, continuing support for these kernels is not something Debian-specific.

    Here are the versions of linux-image-amd64 in Debian currently:

        bullseye (oldoldstable) (kernel): Linux for 64-bit PCs (meta-package)
        5.10.262-1 [security]: amd64
        bookworm (oldstable) (kernel): Linux for 64-bit PCs (meta-package)
        6.1.187-1 [security]: amd64
        bookworm-backports (kernel): Linux for 64-bit PCs (meta-package)
        6.12.95-1~bpo12+1: amd64
        trixie (stable) (kernel): Linux for 64-bit PCs (meta-package)
        6.12.111-1 [security]: amd64
        trixie-backports (kernel): Linux for 64-bit PCs (meta-package)
        7.1.13-1~bpo13+1: amd64
        forky (testing) (kernel): Linux for 64-bit PCs (meta-package)
        7.2.8-1: amd64
        sid (unstable) (kernel): Linux for 64-bit PCs (meta-package)
        7.2.8-1: amd64
    
  • source
  • parent
  • [–] [S] 10 points 9 hours ago*