Comment by pavinjoseph

12 hours ago

Does LOS provide kernel backports or is it limited to userspace?

The vast majority of kernel vulnerabilities aren't backported to end-of-life devices. Special cases are made for certain vulnerabilities with a lot of media coverage. Firmware, kernel drivers, userspace drivers and HALs on end-of-life devices go without patches in general.

They patched CVE-2026-43499 even for out of support kernels[1] so that's something. The bigger problem is CVEs in proprietary components (drivers, blobs, firmware).

[1] eg. https://review.lineageos.org/q/b309b56b8cca20dcf6f678777d3ac...

  • That's very misleading since the vast majority of serious Linux kernel vulnerabilities aren't patched for these end-of-life devices. That vulnerability patched due to media coverage based on their policy to do so. It's no more severe than many of the unpatched ones.

  • That's honestly impressive, enough security for a locked down backup phone.

    • It's very misleading since the vast majority of serious Linux kernel vulnerabilities aren't patched for these end-of-life devices. That vulnerability patched due to media coverage based on their policy to do so. It's no more severe than many of the unpatched ones.