Massive Debian 13 Linux Kernel Security Update Patches 68 Vulnerabilities (9to5linux.com) 47
Slashdot reader prisoninmate shares this report from 9to5Linux:
Coming ten days after the previous Linux kernel security update, which only fixed 12 vulnerabilities that may lead to a privilege escalation, denial of service, or information leaks, the new Debian 13 Linux kernel security update is a massive one, and it patches no less than 68 security vulnerabilities in the Linux 6.12 LTS kernel.
Debian 13 "Trixie" kernel security update are CVE-2026-64530, a use-after-free in the traffic-control subsystem leading to remote denial-of-service with potential for remote code execution, and CVE-2026-64531 (a.k.a. OVSwrap), a local-root vulnerability in the Open vSwitch datapath leading to local privilege escalation to root...
All Debian 13 "Trixie" users are urged to update their installations to Linux kernel 6.12.100-1 as soon as possible.
Debian 13 "Trixie" kernel security update are CVE-2026-64530, a use-after-free in the traffic-control subsystem leading to remote denial-of-service with potential for remote code execution, and CVE-2026-64531 (a.k.a. OVSwrap), a local-root vulnerability in the Open vSwitch datapath leading to local privilege escalation to root...
All Debian 13 "Trixie" users are urged to update their installations to Linux kernel 6.12.100-1 as soon as possible.
Now we'll see how long it takes Ubunto to update (Score:3)
... their packages.
Re:Just wait a cotton pickin' minute. (Score:5, Funny)
He came to my apartment the other day to upgrade my Linux. So he didn't visit your machine? How did you offend him?
Re: (Score:2)
*our Linux. (Remember memes?) He’s making a list, checking it twice, gonna find out who’s naughty or nice.
Re: (Score:2)
That's almost as impressive as the time you got Youtube to come round to your house and film you for their website!
Re: (Score:2)
Re: Just wait a cotton pickin' minute. (Score:3)
6.12 is a SLTS. For the time being Greg -KH (not Linus) pathces it. In the future, when Greg stops, it will be the CIP.
Once the Kernel is patchedM each distro decides when to offer the patched kernel as an update. Some distros take longer than other.
Debian, being the foubdation of so many other distros, is newsworthy in that sense
Re: Just wait a cotton pickin' minute. (Score:2)
Modern Debian is also noteworthy in that backports actually has modern kernels in it. I'm on 7.1.3. Now if only Nvidia could get their dkms script permissions right so that the driver works build right the first time...
Re: (Score:2)
Re: Just wait a cotton pickin' minute. (Score:2)
Debian is always behind, they don't have IBM money or a total disregard for the GPL like redhate does
Re: (Score:2)
Re: Just wait a cotton pickin' minute. (Score:2)
PurpleHat
Re: (Score:2)
According to this, 26.06 LTS got a kernel update fix a couple of weeks ago in the middle of July
https://launchpad.net/ubuntu/+... [launchpad.net]
Granted, 7.0 is no longer supported so patches are being backported by Ubuntu.
Re: (Score:2)
From that page, all three of the standard support LTS releases got updates in mid July.
I assume that page does not include updates to the expanded security maintenance versions given that they all have cutoffs on that page at almost exactly 5 years, and presumably they do provide some nonzero number of kernel updates in that program.
Re: (Score:3)
I don't have a side here. I use both Windows and Linux. Windows pisses me off, Linux pisses me off.
What I care about is how it's hard to have an honest conversation about any of this stuff without it becoming a Microsoft hate-fest or ridiculous assumptions about open source being somehow inherently more secure.
Re: (Score:1)
What I care about is how it's hard to have an honest conversation about any of this stuff without it becoming a Microsoft hate-fest
That's a very, very weird thing to care about unless you're being paid to feel that way. Since Microsoft has done so much shit to so many people in so many ways it's otherwise inexplicable that anyone would come out of the woodwork to defend them. It's like when George Bush pointed out that Hitler had a dog.
Re: (Score:2)
No, I mean because I care about Slashdot and having an interesting, insightful debate here. I know, I'm expected too much, but it happens sometimes.
We are going through a transition where these tools are just becoming available and a massive number of bugs are being fixed, but in future they will be standard for software developers as part of the QA process.
Re: Just waiting (Score:1)
You can't have an insightful discussion involving Microsoft while ignoring their past, present, and probable future of crap.
Re: Just waiting (Score:2)
How boring to see slashdot editors trolling
Re: Just waiting (Score:2)
I will not go into amymojo' motives. For me, I do not need to justify windows, or linux, or macos any more than I need to justify a flathead screwdriver, a torx one, or a pentalobe one.
Each one has their uses, advantages and disadvantages.
PS: Fun fact! Before Pentalobes gained world fame by being adopted by apple, they were used in titanium screws, being used specifically for neck surgery.
Re: (Score:3)
I still consider them terrible people for pushing systemd through.
Re: (Score:2)
So I did look at that article, https://tech.slashdot.org/stor... [slashdot.org], where Microsoft patched 570 security flaws and what you write is a lie, there where not a single comment on it calling Microsoft devs "incompetent morons". A single comment contained "The big underlying issue is why does Microsoft deliver software with so many flaws?" which is quite a lame comment compared with what you claim was written on it.
Then there where a few people commenting on what they found to be bad with Microsoft software which
68 sounds really small by recent comparisons (Score:3)
Isn't everyone patching 100s of vulns every month at the moment?
Re: (Score:2)
That would be fixed in the current tip of the kernel tree.
But there are multiple supported kernel versions, and many vulnerabilities are not present in the older kernels so those will not be backported. Either the feature doesn't exist in the older kernel, or it isn't enabled by default, or there's a dependency on a newer kernel.
Re: (Score:3)
Not all of them are security updates. Not all of them are relevant to the kernel shipped by Debian.
Re: (Score:2)
Re: 68 sounds really small by recent comparisons (Score:2)
This is only the kernel. Meanwhile, in the cases of windows and macos, the vuln count is against the whole OS.
The correct comparison in that case would be against specific distros, not against the kernel.
Why so negative? (Score:5, Insightful)
I am surprised at the many negative comments about the recently found CVEs, about Ubuntu patching LTS and the many other complaints and whining.
Finding these bugs and patching them is a massive security win for Linux and F/OSS operating systems using Linux, and it is awesome to see how many people are working together to deliver these gains to everyone - FOR FREE!
Backporting patches into LTS is pretty thankless but absolutely necessary.
How about a bit more enthusiasm and thankfulness? You are getting an entire OS for free and get to keep (most of) your privacy. When was the last time you helped backport, or donated?
Re: (Score:2)
Exactly. On top of that, a typical apt update/upgrade takes less than a minute. For some users, the need for a reboot after a kernel update is a pain but you can do that when convenient.
Any windows update beyond antivirus seem to take at least 30 minutes, uses half the machines resources, and requires a reboot (or two sometimes).
Re: (Score:2)
Backporting patches into LTS is pretty thankless but absolutely necessary.
It's thankless, yes. Necessary, or even a good idea? I think that's debatable. Actually LTS is probably a good idea... but I'm very skeptical of SLTS. I don't think CIP is going to be successful at keeping 10 year-old kernel versions secure. If you need 10 years, you should either plan to do the work necessary to upgrade to new kernel versions periodically or you should assume that it's just going to be insecure and isolate it or otherwise shield it from attack.
Re: (Score:2)
I don't think CIP is going to be successful at keeping 10 year-old kernel versions secure. If you need 10 years, you should either plan to do the work necessary to upgrade to new kernel versions periodically
The world is full of critical systems that are certified via an extensive (reads: expensive) process for a specific OS version which have an estimated useful life far longer than 10 years. One does not simply upgrade it, and typically the end user may not even be allowed to upgrade it.
Re: (Score:2)
I don't think CIP is going to be successful at keeping 10 year-old kernel versions secure. If you need 10 years, you should either plan to do the work necessary to upgrade to new kernel versions periodically
The world is full of critical systems that are certified via an extensive (reads: expensive) process for a specific OS version which have an estimated useful life far longer than 10 years. One does not simply upgrade it, and typically the end user may not even be allowed to upgrade it.
Everyone has to make their own decisions. I would discourage people from believing that SLTS kernels will be anything like secure by the end of their lifecycle. If that doesn't matter for some application, then fine. If it does matter then arguing that the SLTS kernel must be secure because recertifying is expensive is... not really an argument.
FWIW, in my day job I'm making this same point to people building cars with an expected 20-year lifespan. I think the right conclusion is "Don't use Linux". If
Re: Why so negative? (Score:2)
My understanding of LTS is literally that I will absolutely get critical security patches for a long(er) time.
I do not care about new features or fancy hardware support in LTS but gladly accept whatever trickles down, but the absolute main point for me is rock solid, reliable security patches in an acceptable timely manner. Everything else is secondary.
with enough (mechanical) eyes, all bugs are shallo (Score:2)
It turns out that, now that AI code review has gotten good enough, there is no difference, eyes wise, between open and closed source software.
If anything, for most projects, paid commercial SW (FOSS or not) has an advantage, because they have the money to pay for the mechanical eyes without depending "on the kindness of strangers". The Linux kernel and some other big or well known non-paid-for projects will have no problem getting mechanical eyes. The smaller, or more obscure projects, not so much.
ESR shoul
Re: (Score:1)
Nonsense. And no, AI code review has very much NOT gotten "good enough". It just finds some stuff humans do not find, but it misses most stuff smart humans find.
Re: (Score:1)
Don't worry (Score:1)
LLMs are just finding a few bugs that humans did not because it has a different perspective on things. In a few months, we will be back to mostly or completely human-found bugs, most of which are completely out of reach of LLMs.
Re: (Score:1)
I see the LLM cultists have mod-points again. Here, waste some more.
Re: (Score:2)
And now waste some more. Makes it entirely clear you are dishonest and have no honor.
And a new set of updates just dropped too (Score:2)
I've just compiled the latest 6.18 kernel, released this morning ("Mon Aug 3 11:22:13 2026 +0200" on the 6.18.42 commit message), and there's a 6.6, 6.12 and 7.1 as well. To my layman's eye there appear to be enough "leaks" and "corrupts" in the changelog to warrant security concerns. With the way Linux kernel CVEs work there won't be any yet, the team needs to now look at this new set of releases to judge each commit.
So, expect another Debian kernel update in the next week or so.
bookworm in progress... (Score:2)
I see [debian.org] some of these CVE's are fixed in trixie but not bookworm 6.1.177-1 (yet).
Still other CVE's are fixed in bookworm but not yet in trixie. Seems like a few reboots are in the offing.
First time I've seen several fixes in oldstable before stable. It must be a wild week over there. n.b. fixed, not 'not vulnerable'.
Glad the oldstable crew is hard at work!