Security Patches for the Kernel
#7
Quite regularly, there are so many vulnerabilities in software discovered that as a general rule of thumb I would say that it is a no-go to run any software that does not receive regular updates fully exposed to the internet. Sure, some software is more vulnerable than others. OpenSSH itself could be considered rather secure in this regard, yet it is noteworthy that it also had quite a few issues in the past:

https://www.cvedetails.com/product/585/O...ndor_id=97

But OpenSSH is not the issue as I assume that you still receive updates for OpenSSH. Regarding the Linux kernel, the situation looks worse:

https://www.cvedetails.com/product/47/Li...ndor_id=33

The best way to run "unmaintained" software in the internet is to put it behind something that is maintained, e.g. you could put your system with the unmaintained kernel/sshd behind another system that runs a secure VPN (like wireguard) for which it receives regular updates. Another option could be things like filtering by source IP etc. but - again - these filters must be implemented on a separate (sub)system that *does* receive regular security updates. But I don't think one of these solutions really makes any sense for your particular case.

I recommend switching to a system that is actively maintained. Possible options:

- switching to Armbian
- switchting to any other Distro where all relevant components receive regular updates
- using Debian unstable
- using Debian stable with a kernel from unstable (if you want to go this way you can find my recommendations how to achieve this here: https://www.kulesz.me/post/140-debian-de...4-install/ )

No matter which solution you choose, keep in mind to look for EOL announcements as these usually require manual steps for migration to a new release that is actively supported. The situation might have been more relaxed a few years back, but as you can see from many reports in the news the threats are rising (I am sure you could find scientific data on that as well but I didn't look for any). In the end, running a well-supported OS with regular automated updates also *feels* a lot better so you probably get to sleep better. :-)
  Reply


Messages In This Thread
Security Patches for the Kernel - by kwinz - 12-28-2020, 02:55 PM
RE: Security Patches for the Kernel - by kwinz - 01-06-2021, 06:03 PM
RE: Security Patches for the Kernel - by ryo - 01-06-2021, 11:33 PM
RE: Security Patches for the Kernel - by ryo - 01-07-2021, 10:33 PM
RE: Security Patches for the Kernel - by kwinz - 01-08-2021, 01:39 AM
RE: Security Patches for the Kernel - by kuleszdl - 01-15-2021, 07:37 PM
RE: Security Patches for the Kernel - by DusXMT - 01-16-2021, 12:37 PM
RE: Security Patches for the Kernel - by kuleszdl - 01-16-2021, 05:34 PM
RE: Security Patches for the Kernel - by kwinz - 10-22-2021, 05:45 AM

Possibly Related Threads…
Thread Author Replies Views Last Post
  Linux 5.15 Kernel - openSuse mark1250 0 1,305 12-02-2021, 04:36 PM
Last Post: mark1250
  Debian kernel stuck at 4.4.167 Enig123 5 5,702 12-29-2020, 12:57 PM
Last Post: kwinz
  Arch Linux Arm --> Kernel 5.8 breaks installation as365n4 12 12,424 08-31-2020, 01:41 AM
Last Post: as365n4
  mainline kernel sound support Openwrt lucize 2 4,099 05-01-2020, 05:09 PM
Last Post: PakoSt
  5.3 kernel support? csrf 5 7,163 04-18-2020, 11:34 PM
Last Post: CameronNemo
  Help troubleshooting kernel panic gabrielfin 3 4,685 03-02-2020, 04:18 PM
Last Post: gabrielfin
  need a dts file to set some pins as pulldown interrupts in kernel using a DTO dkebler 0 2,035 02-05-2020, 10:58 PM
Last Post: dkebler
  Any advantages to using the mainline kernel dkebler 0 2,139 11-16-2019, 12:17 PM
Last Post: dkebler
  Does anybody run the mainline kernel? CameronNemo 3 4,689 09-09-2019, 07:56 PM
Last Post: CameronNemo
  ROCK64 Kernel compilation problem cao 0 2,489 01-21-2019, 01:21 AM
Last Post: cao

Forum Jump:


Users browsing this thread: 1 Guest(s)