Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. For the stable distribution (trixie), these problems have been fixed in version 6.12.111-1. We recommend that you upgrade your linux packages. For the detailed security status of linux please refer to its security tracker page at: https://security-tracker.debian.org/tracker/linux Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/
linuxmemes
Hint: :q!
Sister communities:
Community rules (click to expand)
1. Follow the site-wide rules
- Instance-wide TOS: https://legal.lemmy.world/tos/
- Lemmy code of conduct: https://join-lemmy.org/docs/code_of_conduct.html
2. Be civil
- Understand the difference between a joke and an insult.
- Do not harrass or attack users for any reason. This includes using blanket terms, like "every user of thing".
- Don't get baited into back-and-forth insults. We are not animals.
- Leave remarks of "peasantry" to the PCMR community. If you dislike an OS/service/application, attack the thing you dislike, not the individuals who use it. Some people may not have a choice.
- Bigotry of any kind will not be tolerated. This is an LGBTQ+-friendly community -- if that is a problem for you, you should leave.
3. Post Linux-related content
- Including Unix and BSD.
- Non-Linux content is acceptable as long as it makes a reference to Linux. For example, the poorly made mockery of
sudoin Windows. - No porn, no politics, no trolling or ragebaiting.
- Don't come looking for advice, this is not the right community.
4. No recent reposts
- Everybody uses Arch btw, can't quit Vim, <loves / tolerates / hates> systemd, and wants to interject for a moment. You can stop now.
5. π¬π§ Language/ΡΠ·ΡΠΊ/Sprache
- This is primarily an English-speaking community. π¬π§π¦πΊπΊπΈ
- Comments written in other languages are allowed.
- The substance of a post should be comprehensible for people who only speak English.
- Titles and post bodies written in other languages will be allowed, but only as long as the above rule is observed.
6. (NEW!) Regarding public figures
We all have our opinions, and certain public figures can be divisive. Keep in mind that this is a community for memes and light-hearted fun, not for airing grievances or leveling accusations. - Keep discussions polite and free of disparagement.
- We are never in possession of all of the facts. Defamatory comments will not be tolerated.
- Discussions that get too heated will be locked and offending comments removed. Β
Please report posts and comments that break these rules!
Important: never execute code or follow advice that you don't understand or can't verify, especially here. The word of the day is credibility. This is a meme community -- even the most helpful comments might just be shitposts that can damage your system. Be aware, be smart, don't remove France.
Will someone touch me? I'll touch you in return. I am not lost.
From the image, I thought this was an omarchy meme.
Can we please stop making fun of omsloppy already?
Are these real vulnerabilities or are these "When Mars and Jupiter are aligned next to each other and you compile the kernel backwards X might crash" ones?
We use Copilot to review PRs at work. It loves these kinds of scenarios.
The other day, I was adjusting a drop-down site filter to only show options that would work for the given user. It threw up a "critical vulnerability alert" complaining that I "validated" the user's selection based on all options, not just the ones they can view.
First off, it wasn't validation. It was me getting the value of the option. Second, they literally couldn't do anything if they did select one of those options. And third, the user could bypass it about a dozen other ways, even if I designed it to be a validator.
142 critical vulnerabilities
checks inside
denial of service only
Yeah, CVEs are usually nothing when you get down to understanding, especially kernel CVEs, which almost always declares a CVE for almost any bug, because it is easier that trying to think if it is a security issue or not and basically just assume it could be.
Huge pain as in my work we have a security policy where any unpatched CVEs that cannot be updated away must have a fairly significant writeup delving into the nuance of the CVE and what mitigation has been applied or a rationalization of why it isn't a risk and by policy we have to second guess every CVE assessment from our vendor, who we explicitly pay to triage and fix this stuff so we don't have to... They used to at least allow us a pass on "low severity" (that's still pretty flawed), but they decided that didn't sound "tough" enough and now every single one must have an answer. So every month a few people have to spend a few days just reading tons of CVEs that are not yet (and frequently never will be) patched by vendor and rationalize it away for the security team. Sometimes the security team will get odd and demand we build our own from upstream (most recently, vim of all things we were mandated to build from source).
I'm so sorry. I hope the pay is good.
Like the tide, only the moon affects kernel compilation
Hate to break it to you, but the sun also affects tides.
Tap for spoiler

Gravity equation says everything with a mass does... Compiling Gentoo removes the sun from the equation anyway (I chose this over a yo mamma joke, I'm getting wiser it seems)
May I still get the yo mama joke?
Yo mamma so fat it's always high tide when she's at the beach
Oh yeah? Well yo mama teeth are so yellow, when she smiles the traffic slows down!
Oh yeah? Yo mama so stubborn, Waze added a "fine, you drive" instruction
Oh yeah? Yo mama so dumb, she left your dad for her ChatGPT-borne boyfriend
Oh yeah? Yo mama so nice, I wish she was mine! Wait...
Alright alright, you guys are friends now, by the official unofficial internet rules of random interaction, you may kiss now
for anyone too lazy to click the link: CVE-2026-93829 CVE-2026-93830 CVE-2026-97407 CVE-2026-97408 CVE-2026-97409 CVE-2026-97410 CVE-2026-97411 CVE-2026-97412 CVE-2026-97413 CVE-2026-97414 CVE-2026-97415 CVE-2026-97416 CVE-2026-97417 CVE-2026-97418 CVE-2026-97419 CVE-2026-97420 CVE-2026-97421 CVE-2026-97425 CVE-2026-97427 CVE-2026-97428 CVE-2026-97429 CVE-2026-97430 CVE-2026-97434 CVE-2026-97435 CVE-2026-97436 CVE-2026-97437 CVE-2026-97438 CVE-2026-97439 CVE-2026-97440 CVE-2026-97441 CVE-2026-97442 CVE-2026-97443 CVE-2026-97444 CVE-2026-97445 CVE-2026-97446 CVE-2026-97448 CVE-2026-97449 CVE-2026-97450 CVE-2026-97451 CVE-2026-97452 CVE-2026-97453 CVE-2026-97454 CVE-2026-97455 CVE-2026-97456 CVE-2026-97472 CVE-2026-97473 CVE-2026-97475 CVE-2026-97476 CVE-2026-97481 CVE-2026-97482 CVE-2026-97483 CVE-2026-97484 CVE-2026-97485 CVE-2026-97486 CVE-2026-97487 CVE-2026-97488 CVE-2026-97489 CVE-2026-97490 CVE-2026-97491 CVE-2026-97492 CVE-2026-97494 CVE-2026-97495 CVE-2026-97496 CVE-2026-97497 CVE-2026-97500 CVE-2026-97502 CVE-2026-97504 CVE-2026-97505 CVE-2026-97506 CVE-2026-97507 CVE-2026-97508 CVE-2026-97509 CVE-2026-97510 CVE-2026-97512 CVE-2026-97514 CVE-2026-97516 CVE-2026-97517 CVE-2026-97518 CVE-2026-97520 CVE-2026-97521 CVE-2026-97522 CVE-2026-97523 CVE-2026-97524 CVE-2026-97539 CVE-2026-97540 CVE-2026-97541 CVE-2026-97542 CVE-2026-97543 CVE-2026-97544 CVE-2026-97545 CVE-2026-97546 CVE-2026-97547 CVE-2026-97551 CVE-2026-97552 CVE-2026-97555 CVE-2026-97556 CVE-2026-97557 CVE-2026-97560 CVE-2026-97562 CVE-2026-97564 CVE-2026-97568 CVE-2026-97572 CVE-2026-97573 CVE-2026-97575 CVE-2026-97576 CVE-2026-97577 CVE-2026-97578 CVE-2026-97579 CVE-2026-97581 CVE-2026-97582 CVE-2026-97583 CVE-2026-97584 CVE-2026-97587 CVE-2026-97592 CVE-2026-97595 CVE-2026-97596 CVE-2026-97598 CVE-2026-97599 CVE-2026-97600 CVE-2026-97601 CVE-2026-97602 CVE-2026-97604 CVE-2026-97605 CVE-2026-97606 CVE-2026-97607 CVE-2026-97608 CVE-2026-97611 CVE-2026-97612 CVE-2026-97613 CVE-2026-97616 CVE-2026-97617 CVE-2026-97899 CVE-2026-97900 CVE-2026-97902 CVE-2026-97904 CVE-2026-97905 CVE-2026-97907 CVE-2026-97908 CVE-2026-97909 CVE-2026-97910 CVE-2026-97915 CVE-2026-97916 CVE-2026-97917 CVE-2026-97920 CVE-2026-97921 CVE-2026-97922 CVE-2026-97923 CVE-2026-97924 CVE-2026-97925 CVE-2026-97926 CVE-2026-97927 CVE-2026-97929 CVE-2026-97930 CVE-2026-97931 CVE-2026-97936 CVE-2026-97940 CVE-2026-97945 CVE-2026-97948 CVE-2026-97951 CVE-2026-97952 CVE-2026-97953 CVE-2026-97954 CVE-2026-97957 CVE-2026-97958 CVE-2026-97959 CVE-2026-97961 CVE-2026-97963 CVE-2026-97964 CVE-2026-97965 CVE-2026-97966 CVE-2026-97967 CVE-2026-97968 CVE-2026-97969 CVE-2026-97970 CVE-2026-97973 CVE-2026-97976 CVE-2026-97977 CVE-2026-97978 CVE-2026-97979 CVE-2026-97981 CVE-2026-97982 CVE-2026-97984 CVE-2026-97985 CVE-2026-97986 CVE-2026-97987 CVE-2026-97990 CVE-2026-97991 CVE-2026-97992 CVE-2026-97993 CVE-2026-97994 CVE-2026-97995 CVE-2026-97996 CVE-2026-97998 CVE-2026-98001 CVE-2026-98006 CVE-2026-98007 CVE-2026-98008 CVE-2026-98009 CVE-2026-98010 CVE-2026-98011 CVE-2026-98012 CVE-2026-98013 CVE-2026-98014 CVE-2026-98015 CVE-2026-98016 CVE-2026-98017 CVE-2026-98018 CVE-2026-98020 CVE-2026-98021 CVE-2026-98022 CVE-2026-98023 CVE-2026-98024 CVE-2026-98025 CVE-2026-98026 CVE-2026-98027 CVE-2026-98028 CVE-2026-98029 CVE-2026-98030 CVE-2026-98031 CVE-2026-98037 CVE-2026-98039 CVE-2026-98041 CVE-2026-98045 CVE-2026-98046 CVE-2026-98051 CVE-2026-98052 CVE-2026-98054 CVE-2026-98055 CVE-2026-98056 CVE-2026-98057 CVE-2026-98059 CVE-2026-98063 CVE-2026-98064 CVE-2026-98066 CVE-2026-98068 CVE-2026-98069 CVE-2026-98070 CVE-2026-98071 CVE-2026-98072 CVE-2026-98074 CVE-2026-98075 CVE-2026-98076 CVE-2026-98077 CVE-2026-98078 CVE-2026-98080 CVE-2026-98081 CVE-2026-98082 CVE-2026-98083 CVE-2026-98086 CVE-2026-98088 CVE-2026-98089 CVE-2026-98090 CVE-2026-98091 CVE-2026-98092 CVE-2026-98094 CVE-2026-98095 CVE-2026-98096 CVE-2026-98097 CVE-2026-98098 CVE-2026-98102 CVE-2026-98103 CVE-2026-98104 CVE-2026-98105 CVE-2026-98107 CVE-2026-98108 CVE-2026-98109 CVE-2026-98110 CVE-2026-98111 CVE-2026-98113 CVE-2026-98114 CVE-2026-98116 CVE-2026-98121 CVE-2026-98122 CVE-2026-98123 CVE-2026-98126 CVE-2026-98127 CVE-2026-98128 CVE-2026-98129 CVE-2026-98130 CVE-2026-98142 CVE-2026-98151 CVE-2026-98152 CVE-2026-98154 CVE-2026-98155 CVE-2026-98157 CVE-2026-98158 CVE-2026-98159 CVE-2026-98160 CVE-2026-100070 CVE-2026-100071 CVE-2026-100075 CVE-2026-100078 CVE-2026-100079 Debian Bug : 1108860
it also says:
For the stable distribution (trixie), these problems have been fixed in version 6.12.111-1.

That is indeed a great deal of CVEs.
and if i am too lazy to read?
TL;DR - Jesus, that's a lot of CVEs.
Can you translate that for other religions and atheists, too?
"shit's fucked"
Some of them are 2024 and 2025. How come they made it into this list?
Some of them aren't actually bugs but just "security" people wanting to get a longer epenis by flagging issues like "maximum priority, it allows to read the ssh private key!!!1!!" And then the details are like "when typing more ./ssh/id_rsa the user private key is shown, terminal should intercept and block request"
And with LLMs it's even worse as they're directed to find nitpicks at all costs
What's an e-penis?
Donβt know, but Iβm sure mine is bigger than yours.
Haha! Got me! :p
An e-penis is to a penis what an e-bike is to a bike.
So... you can ride it faster?
Maybe it speeds up when you twist the handle
Serious answer: Theyβre low priority bullshit rather than practical security concerns.
βThis method crashes if you intentionally feed it malformed data!!β- type of stuff.
Curl guy has written about a couple of these stupid CVEs, for example: https://daniel.haxx.se/blog/2023/09/05/bogus-cve-follow-ups/
One I recall was that if you asked curl to write out c code example of libcurl usage, you could get it to write out arbitrary code of your choosing. Note that this required you to have write permission and curl and then with your malicious c code, you then had to compile it and make it executable and run it yourself. So a very roundabout way to use curl as a text editor, and they considered it an arbitrary code execution issue, despite not actually executing the code.
The following is my guess, I don't know what the Debian project's selection criteria for security advisories are.
Taking the first one as an example, CVE-2024-52560 is a bug that affects version 5.15 of the Linux Kernel. The oldest version of Debian that's still in general LTS is Debian 11 which shipped with Linux 5.10. So they are still supporting releases that may be running the affected kernel and can't upgrade the kernel for some reason, but would still benefit from some downstream patches that mitigate the exposure of the kernel bug.
Looking through these I don't really see a big commonality.
Interesting that for some of them only trixie is affected, not bookworm. Maybe that's down to bugs in newer sections of code.
https://security-tracker.debian.org/tracker/CVE-2024-52560
https://security-tracker.debian.org/tracker/CVE-2024-58094
https://security-tracker.debian.org/tracker/CVE-2024-58095
https://security-tracker.debian.org/tracker/CVE-2025-21817
https://security-tracker.debian.org/tracker/CVE-2025-22104
https://security-tracker.debian.org/tracker/CVE-2025-22108
https://security-tracker.debian.org/tracker/CVE-2025-22127
https://security-tracker.debian.org/tracker/CVE-2025-38203
https://security-tracker.debian.org/tracker/CVE-2025-38205
https://security-tracker.debian.org/tracker/CVE-2025-38206
https://security-tracker.debian.org/tracker/CVE-2025-38237
https://security-tracker.debian.org/tracker/CVE-2025-38621
https://security-tracker.debian.org/tracker/CVE-2025-39833
https://security-tracker.debian.org/tracker/CVE-2025-39925
https://security-tracker.debian.org/tracker/CVE-2025-40064
https://security-tracker.debian.org/tracker/CVE-2025-40102
https://security-tracker.debian.org/tracker/CVE-2025-40139
https://security-tracker.debian.org/tracker/CVE-2025-40168
At least they are aware π°

Much worse if there are no CVE's...
Nothing to see here, citizen. Move along.
Escort carriers?
wait why are there 2024 cves?
moth will answer you tomorrow, assuming moth remembers and finds time, is why
I saw this in the CISA announcement today. I was wondering if either:
- the project to port the kernel to rust Or
- people using AI to look for vulnerabilities
Caused the huge list?
(IBM had a ton too)
Given 1 isn't true, it's a rather easy guess
More the fact that it's Debian and they still support huge amounts of ancient stuff. There are year's old ones in the list... alas, Debian still supports kernels like 5.10LTS. And backporting fixes doesn't get easier over time.
Itβs the latter; the kernel CVE report counts have gone through the roof in the past few years.
No one is porting the whole kernel to rust (as part of the official project, at least).