Remix.run Logo
▲ sippingabonedry 2 hours ago

Will everyone chill the F out for a minute?

These get released every few weeks. Tons of CVEs. If a kernel developer farts in the forest, does anyone hear it?

August saw separate Debian kernel updates released four days apart. Does anyone even reboot that often?

I have three kernels installed over the last 45 days or so and I probably missed a few.

▲nightfly 2 hours ago | parent | next [-]

I've been doing Linux sys-admin work for 10+ years. Used to be I could read the full report on what ever vulnerabilities came out and triage which servers needed to be updated now and which could wait. A few years ago notifications started having so many it would take more time/effort to read everything than it would to patch everything. With this notification there's even ten times more...

▲Gigachad 21 minutes ago | parent | next [-]

That's because the methodology changed in 2024

>Note, due to the layer at which the Linux kernel is in a system, almost any bug might be exploitable to compromise the security of the kernel, but the possibility of exploitation is often not evident when the bug is fixed. Because of this, the CVE assignment team are overly cautious and assign CVE numbers to any bugfix that they identify. This explains the seemingly large number of CVEs that are issued by the Linux kernel team.

https://lwn.net/Articles/961961/

▲sippingabonedry an hour ago | parent | prev [-]

The amount of updates on Debian "stable" has become ridiculous, it's a daily rolling release of backports at this point.

Microsoft kinda got this right by doing it once a month, unless it's something horribly bad, you can plan your maintenance around a predictable calendar.

▲vortext an hour ago | parent [-]

You can choose to only install updates that require a restart once a month on Debian, then it's the same.

▲tclancy 42 minutes ago | parent | prev | next [-]

Regarding the fart question, it depends on the audio driver and the underlying codec. While you would think “free as in beer” would make for truly resonant flatulence, only truly letting loose (plus a Bic lighter) brings real enlightenment.

▲SoftTalker an hour ago | parent | prev [-]

We're considering weekly reboots at work now with the pace of kernel updates coming out, and the speed with which vulnerabilities are getting exploited.

▲sippingabonedry an hour ago | parent | next [-]

There is exactly one CVE in the entire list that is high severity, and it affects an obscure IBM NIC driver for big iron systems used in companies with more money than brains.

You can skip the Xanax this week.

▲Gigachad 19 minutes ago | parent [-]

Problem is it takes more effort to read the CVE list and work out if you have one of the drivers impacted loaded than it does to just update the kernel.

▲seany an hour ago | parent | prev [-]

Weekly? 12 or 24hr cadence for upgrades isn't that crazy in some places for cluster hosts...