Live data from Hacker News

Red Hat reports security issue in Linux Kernel which was fixed 17 months prior

openwall.com

11–20 of 78 posts

Re: Red Hat reports security issue in Linux Kernel which was fixed 17 months prior

#11

Why don't Red Hat et al use the LTS kernels?

Note that Red Hat, SUSE, and Canonical all don't use them. They maintain their own kernel trees with their modifications. These kernel teams have different priorities:

* stable ABI within a timespan (RH, SUSE)

* feature backports based on customer demand (all three)

* out of tree goop (Canonical)

I've also heard from others (though notably, not folks specifically at these companies) that longterm kernels are iffier than regular stable kernels because people come out of the woodwork to push weird stuff for longterm kernels, which destabilizes things more than with regular stable kernels.

Re: Red Hat reports security issue in Linux Kernel which was fixed 17 months prior

#12
post #9

I really hate the fact that RHEL updates kernels so slowly. This becomes very painful when your product cannot take advantage of some advanced kernel features just because you have customers running RHEL :(.

Is there anyway you can use a different kernel? The kernel is really easily replaceable in other distros. I don't know much about RHEL.

Re: Red Hat reports security issue in Linux Kernel which was fixed 17 months prior

#13

Why don't Red Hat et al use the LTS kernels?

Note that Red Hat, SUSE, and Canonical all don't use them. They maintain their own kernel trees with their modifications. These kernel teams have different priorities: * stable ABI within a timespan (RH, SUSE) * feature backports based on customer demand (all three) * out of tree goop (Canonical) I've also heard from others (though notably, not folks specifically at these companies) that longterm kernels are iffier t…

Seems like even Arch maintains it's own kernel. Not uncommon for distros to do it at all.

Re: Red Hat reports security issue in Linux Kernel which was fixed 17 months prior

#14
post #9

I really hate the fact that RHEL updates kernels so slowly. This becomes very painful when your product cannot take advantage of some advanced kernel features just because you have customers running RHEL :(.

Try SLES; enterprise support, recent kernels.

Re: Red Hat reports security issue in Linux Kernel which was fixed 17 months prior

#15
post #9

I really hate the fact that RHEL updates kernels so slowly. This becomes very painful when your product cannot take advantage of some advanced kernel features just because you have customers running RHEL :(.

Is there anyway you can use a different kernel? The kernel is really easily replaceable in other distros. I don't know much about RHEL.

No, you can't do that in RHEL. It would invalidate support.

Re: Red Hat reports security issue in Linux Kernel which was fixed 17 months prior

#16
post #15

Earlier quoted context omitted.

Is there anyway you can use a different kernel? The kernel is really easily replaceable in other distros. I don't know much about RHEL.

No, you can't do that in RHEL. It would invalidate support.

O'rly?

Re: Red Hat reports security issue in Linux Kernel which was fixed 17 months prior

#17

Why don't Red Hat et al use the LTS kernels?

Note that Red Hat, SUSE, and Canonical all don't use them. They maintain their own kernel trees with their modifications. These kernel teams have different priorities: * stable ABI within a timespan (RH, SUSE) * feature backports based on customer demand (all three) * out of tree goop (Canonical) I've also heard from others (though notably, not folks specifically at these companies) that longterm kernels are iffier t…

What is the difference between a "longterm kernel" and a "regular stable kernel"?

Re: Red Hat reports security issue in Linux Kernel which was fixed 17 months prior

#18
post #7

Why don't Red Hat et al use the LTS kernels?

They feel like they know better and do not want all of the fixes that the LTS kernels provide for some crazy reason. I suggest you contact them if you rely on a RHEL kernel to ask them why they do this, it's always seemed crazy. Note, I'm the person who does the LTS kernel releases, maybe they just don't like me :)

I'm certain that Red Hat and our kernel developers have no animosity towards you, in fact it's completely the opposite. You're well known in the community not just for this but for maintaining and writing countless drivers and loads of other great work in the kernel.

Fedora does use the LTS kernels.

Re: Red Hat reports security issue in Linux Kernel which was fixed 17 months prior

#19

Your headline's misleading. Red Hat knows it's long been fixed in the LTS kernels, but it still needs patching in the RHEL kernels. Generally speaking, current LTS kernels are not used in older Linux distros.

Moderators can of course change the title, I don't think it's misleading and I was not trying to be. I guess 'reports' could be changed into 'finds' and it could be mentioned that it was found 'in its Linux kernel', not sure when the character limit would hit.

'current LTS kernels are not used in older Linux distros' - not sure what your point is with this. They absolutely could have used / can use LTS kernels if they wanted to or they could merge LTS-kernel changes which they apparently don't.

Re: Red Hat reports security issue in Linux Kernel which was fixed 17 months prior

#20
post #7

Why don't Red Hat et al use the LTS kernels?

They feel like they know better and do not want all of the fixes that the LTS kernels provide for some crazy reason. I suggest you contact them if you rely on a RHEL kernel to ask them why they do this, it's always seemed crazy. Note, I'm the person who does the LTS kernel releases, maybe they just don't like me :)

It could also be motivated by the fact that it's not entirely wise to base an entire multibillion dollar business around whatever text a non-employee happens to push to a repo you don't control.
Post reply on HN