Skip to content

Bump kernel to 6.12 LTS + Debian snapshot 20260519#150

Open
MoeMahhouk wants to merge 1 commit into
mainfrom
moe/kernel-6.12-lts-bump
Open

Bump kernel to 6.12 LTS + Debian snapshot 20260519#150
MoeMahhouk wants to merge 1 commit into
mainfrom
moe/kernel-6.12-lts-bump

Conversation

@MoeMahhouk
Copy link
Copy Markdown
Member

Security hardening and snapshot refresh. Linux 6.19 is upstream EOL. Move to the 6.12 LTS line via the trixie-security pocket, which carries Debian-backported fixes for four recent kernel CVEs:

  • CVE-2026-31431 (copy.fail / algif_aead) -- crypto: algif_aead - Revert to operating out-of-place (in 6.12.85-1).
  • CVE-2026-46300 (Fragnesia / XFRM ESP-in-TCP) -- xfrm: esp: avoid in-place decrypt on shared skb frags (Debian cherry-pick added in 6.12.86-1).
  • "Dirty Frag" / Copy Fail 2 -- same xfrm-esp shared-frag series; covered by the same cherry-pick.
  • CVE-2026-46333 (ssh-keysign-pwn / __ptrace_may_access dumpable) -- ptrace: slightly saner 'get_dumpable()' logic (in 6.12.88-1).

Resulting package: linux 6.12.88-1 from trixie-security.
Snapshot: 20260519T000413Z (latest debian-security snapshot
confirmed to contain 6.12.88-1; same timestamp
resolves on the main debian archive).

Changes:

  • shared/mkosi.conf: KERNEL_VERSION 6.19 -> 6.12.
  • shared/mkosi.build.d/10-kernel.sh: drop the /trixie-backports suite pin from the apt-get install; 6.12 lives in main + security, not backports.
  • shared/mkosi.sync.d/10-setup-apt.sh: emit a second sources block for trixie-security (snapshot mirror archive/debian-security/, or security.debian.org for unpinned builds).
  • images/{flashbox-l1,flashbox-l2,l2-op-rbuilder,l2-op-rbuilder-bproxy, l2-simulator}.conf: Snapshot bumped to 20260519T000413Z.

References:
https://snapshot.debian.org/package/linux/6.12.88-1/
https://snapshot.debian.org/archive/debian-security/20260519T000413Z/

Security hardening and snapshot refresh. Linux 6.19 is upstream EOL.
Move to the 6.12 LTS line via the trixie-security pocket, which carries
Debian-backported fixes for four recent kernel CVEs:

  - CVE-2026-31431 (copy.fail / algif_aead) -- crypto: algif_aead -
    Revert to operating out-of-place (in 6.12.85-1).
  - CVE-2026-46300 (Fragnesia / XFRM ESP-in-TCP) -- xfrm: esp: avoid
    in-place decrypt on shared skb frags (Debian cherry-pick added
    in 6.12.86-1).
  - "Dirty Frag" / Copy Fail 2 -- same xfrm-esp shared-frag series;
    covered by the same cherry-pick.
  - CVE-2026-46333 (ssh-keysign-pwn / __ptrace_may_access dumpable) --
    ptrace: slightly saner 'get_dumpable()' logic (in 6.12.88-1).

Resulting package: linux 6.12.88-1 from trixie-security.
Snapshot:          20260519T000413Z (latest debian-security snapshot
                   confirmed to contain 6.12.88-1; same timestamp
                   resolves on the main debian archive).

Changes:

  - shared/mkosi.conf: KERNEL_VERSION 6.19 -> 6.12.
  - shared/mkosi.build.d/10-kernel.sh: drop the /trixie-backports
    suite pin from the apt-get install; 6.12 lives in main + security,
    not backports.
  - shared/mkosi.sync.d/10-setup-apt.sh: emit a second sources block
    for trixie-security (snapshot mirror archive/debian-security/,
    or security.debian.org for unpinned builds).
  - images/{flashbox-l1,flashbox-l2,l2-op-rbuilder,l2-op-rbuilder-bproxy,
    l2-simulator}.conf: Snapshot bumped to 20260519T000413Z.

References:
  https://snapshot.debian.org/package/linux/6.12.88-1/
  https://snapshot.debian.org/archive/debian-security/20260519T000413Z/
@MoeMahhouk MoeMahhouk changed the title Bump kernel to 6.12 LTS + Debian snapshot 20260519 to fix 4 kernel CVEs Bump kernel to 6.12 LTS + Debian snapshot 20260519 May 19, 2026
@MoeMahhouk MoeMahhouk marked this pull request as ready for review May 19, 2026 20:44
@MoeMahhouk MoeMahhouk requested a review from a team as a code owner May 19, 2026 20:44
@0x416e746f6e
Copy link
Copy Markdown
Member

perhaps not a "bump" but rather roll-back?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants