debian 13.5, kernel Linux 6.12.90+deb13.1-amd64 and Dirty Frag (CVE-2026-43284, CVE-2026-43500). Do I need to patch?

I just read about this exploit and don't know if I have to do anything at all.

please eli5 because I'm not good at this.

25 points · 7 comments · view on lemmy.world

7 Comments

dan@upvote.au · 13 pts · 93d (4 replies)

Make sure you have the security repo enabled in /etc/apt/sources.list. It should be enabled by default. Just search that file for "security"

Then just run apt update, apt upgrade, and reboot.

deleted@lemmy.world · -2 pts · 93d (3 replies)

I think apt upgrade wouldn’t upgrade the kernel. The correct one is apt dist-upgrade.

Edit: apt update would patch the kernel.

Ooops@feddit.org · 3 pts · 93d (1 reply)

upgrade to next kernel version != patch the kernel with backported security fixes

deleted@lemmy.world · 2 pts · 93d

Thank you for your reply.

I saw a post lately regarding this and my Debian kernel update was held back because I thought apt upgrade upgrades everything. After I ran apt dist-upgrade it was upgraded.

The post: https://lemmy.world/post/46322168

dan@upvote.au · 3 pts · 92d

You're thinking of apt full-upgrade. dist-upgrade is the old name for it.

The only difference between upgrade and full-upgrade is that full-upgrade will delete packages if necessary (like if you have a program installed that conflicts with a new version of another program), whereas upgrade will never do that. upgrade is safer for day-to-day updates.

If you do an upgrade and there's packages that need you to run full-upgrade, you'll see a message saying that some packages have been held back.

full-upgrade is mostly safe. You just need to read the output carefully before continuing.

bjoern_tantau@swg-empire.de · 5 pts · 93d

Debian is pretty good at ensuring security fixes are applied to their software. Even if the specific version of a program (or the kernel) is old they make sure to include security fixes of newer versions.

So like the other comment said just upgrading like normal should be enough.

novafunc@discuss.tchncs.de · 4 pts · 93d

6.12.90 is the latest release, you’re good. Just make sure you’ve rebooted since installing it.