pleroma.debian.social

pleroma.debian.social

If you're running Debian, take the update right now.

https://lwn.net/Articles/1097401/

EDIT: muting

@veronica Are those actual problems or "vibecoded ai slop found something maybe" problems? Hate that i can't tell these days.

@workingclassgames Does it matter? If people depend on your work, you don't want to be delaying updates like this

Also, don't be surprised if there are additional updates coming shortly. This might be a scenario where we're going to be restarting frequently.

@veronica How does this affect downstream distros like Proxmox (which uses a later 7.x kernel) and Ubuntu? I've not dove much into the kernel side of the OS's before and just took whatever apt/ yum gave me

@DefectiveWings Depends on how they get updates, standard advice is to follow their security disclosures and update as soon as it's offered.

@veronica <10 pages of CVEs fixed> what the fuck.

oh right Linux is slopware now

@JennyFluff that doesn't mean we should ignore updates though, lol

@JennyFluff @veronica
LLMs aside, this is the result of a longstanding source of tension between Linux (and others) over what gets considered a security issue and its assigned severity. It's all a mess and Linux decided to go with malicious compliance and just call all bugs potential security vulnerabilities.

(very sorry if I just "mansplained" that; it didn't occur to me until I hit enter)

@jbowen @veronica (I don't think you have)

omg I'm muting this due to replyfolk telling me how to server

@veronica

I sighed and updated some servers.

@veronica
"Several vulnerabilities have been discovered in the Linux kernel "

That "several" is one way of putting it!

@veronica
It's not just Debian though, these are all upstream CVEs...
replies
0
announces
0
likes
0

@workingclassgames @veronica it’s “the Linux kernel developers don’t believe in CVEs, and because people complained they didn’t assign CVEs to security issues, they now assign a CVE to every single kernel patch no matter whether it is security-relevant or not”

@veronica I sure "love" how completely useless the description in the article is. One sure knows just what risks one is in fact exposed to⸮

Instead we get a flood of nonsense.