← Back to context

Comment by deng

14 hours ago

I was secretly hoping they'd stop supporting the Pixel 4a so I would have a reason to get a new phone, but no, still there in the list of supported devices. So I guess I'll just keep using that thing another year... Anyway: big thanks to the Lineage maintainers, keeping so many phones from landfill!

If you need a reason, the modem and the baseband firmware have several unpatched vulnerabilities on that model, which is not something that an Android update can resolve.

  • Is there an easy way to tell if there are unpatched vulnerabilities in my phone's modem and baseband?

    • Based on the amount of modem CVEs posted in the monthly Android security bulletins, I think it's safe to assume that if you are no longer getting updates then there are unpatched vulnerabilities in them.

      6 replies →

  • In a practical sense, what are the consequences of that? If you're careful about not installing random shit on your phone?

    • It has remotely exploitable vulnerabilities in the firmware, Linux kernel, kernel drivers, userspace drivers and HALs. Those don't require installing anything on your device to exploit. There are publicly available proof of concept exploits for a bunch of these vulnerabilities.

  • Well, it might be worth it reversing firmwares now with UART pins connected. A lot has changed in (agentic) reverse engineering.

    BRB gonna try this out on my old Fairphone

I too have a 4a that is still ticking thanks to Lineage!

The only problem I've discovered is that group texts sometimes don't work (I can't see others' replies or worst case I don't receive the group text at all). Not sure if anyone else has run into this, seems like it could be related to RCS and unlocked bootloader not playing nice.

  • I have stock Android on a Pixel 10 and RCS group texts don't work here either. Some people just can't be added to the group and some people just don't receive the texts.

    It's so bad.

What happened there, ... After official support by Google for the 4a stopped, I remember checking LOS out, and found that it wasn't supported there either. Did I hallucinate that, or did LOS resume support afterwards? Or maybe I'm mixing up LOS and graphene

I wish I could still use my Pixel 4a but the battery is pretty much dead and it's too much money to replace it

I have a OnePlus 7, and it's chugging along on LOS, otherwise I would be without a smartphone. Heh, fortunately it's still on the supported list

I was secretly hoping I didn't misread and Linaro wiki would be up again, I really wish we could just install mainline linux on those Android phones...

Does LOS provide kernel backports or is it limited to userspace?

  • The vast majority of kernel vulnerabilities aren't backported to end-of-life devices. Special cases are made for certain vulnerabilities with a lot of media coverage. Firmware, kernel drivers, userspace drivers and HALs on end-of-life devices go without patches in general.

  • They patched CVE-2026-43499 even for out of support kernels[1] so that's something. The bigger problem is CVEs in proprietary components (drivers, blobs, firmware).

    [1] eg. https://review.lineageos.org/q/b309b56b8cca20dcf6f678777d3ac...

    • That's very misleading since the vast majority of serious Linux kernel vulnerabilities aren't patched for these end-of-life devices. That vulnerability patched due to media coverage based on their policy to do so. It's no more severe than many of the unpatched ones.