Comment by gruez

9 hours ago

They patched CVE-2026-43499 even for out of support kernels[1] so that's something. The bigger problem is CVEs in proprietary components (drivers, blobs, firmware).

[1] eg. https://review.lineageos.org/q/b309b56b8cca20dcf6f678777d3ac...

That's very misleading since the vast majority of serious Linux kernel vulnerabilities aren't patched for these end-of-life devices. That vulnerability patched due to media coverage based on their policy to do so. It's no more severe than many of the unpatched ones.

That's honestly impressive, enough security for a locked down backup phone.

  • It's very misleading since the vast majority of serious Linux kernel vulnerabilities aren't patched for these end-of-life devices. That vulnerability patched due to media coverage based on their policy to do so. It's no more severe than many of the unpatched ones.