Poor coordination
Poor coordination
Posted Apr 30, 2026 10:06 UTC (Thu) by wodny (subscriber, #73045)Parent article: A security bug in AEAD sockets
Unfortunately the coordination process seems to be poor or non-existent[1]. Xint recommends upgrading[2] while there are no upgrades available yet. In particular Debian Stable and Oldstable are still vulnerable[3] as they use 6.1 and 6.12 kernels not yet patched upstream (at least that was the case yesterday).
[1]: https://www.openwall.com/lists/oss-security/2026/04/30/10
[2]: https://x.com/spendergrsec/status/2049616316475003243
[3]: https://security-tracker.debian.org/tracker/CVE-2026-31431
