Don't panic! It's only 60 Linux CVE security bulletins a week

Discussion in 'all things UNIX' started by ronjor, Aug 21, 2024.

  1. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    177,020
    Location:
    Texas
    Steven Vaughan-Nichols, Senior Contributing Editor Aug. 21, 2024
     
  2. reasonablePrivacy

    reasonablePrivacy Registered Member

    Joined:
    Oct 7, 2017
    Posts:
    2,222
    Location:
    Member state of European Union
    Article is relatively good, thought they should expand on downstream distributions being the middleman. Because most Linux users don't build their own kernel from source.
     
  3. summerheat

    summerheat Registered Member

    Joined:
    May 16, 2015
    Posts:
    2,244
    That‘s why I‘m using Arch Linux. Always having the latest kernel (and latest apps and libraries) with the newest security patches is reassuring.
     
  4. reasonablePrivacy

    reasonablePrivacy Registered Member

    Joined:
    Oct 7, 2017
    Posts:
    2,222
    Location:
    Member state of European Union
    Yeah, rolling release distros are probably latest thus greatest when it comes to security. However I never really felt threaten enough to use them, because major traditional "big" release distros do backport patches often and fast enough for me.
    Given that I use free version of Gnu/Linux disteos like openSUSE, what I really miss is live patch feature. Commercial releases do come with access to live patches, so you can patch kernel without doing any reboot!
     
  5. Stupendous Man

    Stupendous Man Registered Member

    Joined:
    Aug 1, 2010
    Posts:
    3,097
    Location:
    the Netherlands
    Canonical offers live kernel updates (Livepatch service) as one of the features of Ubuntu Pro, for Ubuntu and Ubuntu flavors. I use Ubuntu Pro for its Expanded Security Maintenance (ESM) feature. I disabled the Ubuntu Pro Livepatch client service, as I have no problem rebooting my two systems to deploy kernel updates. However, I understand how Livepatch is most welcome in other situations to minimize downtime and unplanned reboots.
     
  6. reasonablePrivacy

    reasonablePrivacy Registered Member

    Joined:
    Oct 7, 2017
    Posts:
    2,222
    Location:
    Member state of European Union
    Ok, however live patching wasn't developed by them.
    https://www.redhat.com/en/topics/linux/what-is-linux-kernel-live-patching
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.