Shared libraries
Shared libraries
Posted Nov 25, 2025 15:10 UTC (Tue) by paulj (subscriber, #341)In reply to: Shared libraries by farnz
Parent article: APT Rust requirement raises questions
Which scenario is the more common? Which has the better track record at quickly updating to fix bugs? The random statically linked upstream-packaged apps or the Linux distros? I'd say the distros.
But let's say Linux distros are just average. Say we have 100 upstream-packaged statically-linked apps, and 100 apps using the distro shared library... ~50 of the upstream apps will update before the distro, and ~50 after - with a long tail. So - even if distros are not very good at shipping security updates, the statically linked approach will still leave you with a number of vulnerable apps for a long time to come.
