Posts by tomasv@fosstodon.org
(DIR) Post #B5vtMPUJUbn4JY1xvE by tomasv@fosstodon.org
0 likes, 0 repeats
@AndresFreundTec @thesamesam @mgorny IMHO the cadence of the releases is not the main problem here - in a way, that's not entirely up to the kernel folks, it depends on what issues get discovered/reported, if there's an agreement on when it gets public, etc. Having more frequent releases with as many fixes as possible is probably the better option, but it also means it's somewhat futile - you can't rely on the kernel alone, you need other defenses too (even if you can upgrade that often).
(DIR) Post #B5vtMQ0DZzJLuUxReS by tomasv@fosstodon.org
0 likes, 0 repeats
@AndresFreundTec @thesamesam @mgorny I think the bigger issue is the strange definition of what "LTS" means, and what people assume it to mean. Because from the descriptions I found, LTS means "actively maintained and provided with security updates" but it seems it means "some security updates, maybe". Which is not great, I guess?FWIW I understand the number of fixed issues is likely overwhelming. But then maybe not having LTS kernels would be better ...
(DIR) Post #B5vtMQ8j4M7IKswEue by tomasv@fosstodon.org
0 likes, 0 repeats
@AndresFreundTec @thesamesam @mgorny True, but I'm afraid it's not practical. Someone needs to make those assessments, it's hard to determine the impact, and it's likely very time consuming. Even before the current onslaught of reports. I'd imagine this is why NIST recently gave up on enriching the CVEs.