Re: Does Debian needs a big overhaul to how it does things?
Arnox <[email protected]>
| Newsgroups | gmane.linux.debian.devel.general |
|---|---|
| Organization | Sanctuary |
| Message-ID | <[email protected]> |
To be specific, the KDE incident occurred on June 4th, 2026. I had spotted on the KDE security advisories page (https://kde.org/info/security/#advisories) that there was at least five critical security holes in Okular reported in the middle of May, also that year. Here are the exact advisories in question: https://kde.org/info/security/advisory-20260511-5.txt https://kde.org/info/security/advisory-20260511-4.txt https://kde.org/info/security/advisory-20260511-3.txt https://kde.org/info/security/advisory-20260511-2.txt https://kde.org/info/security/advisory-20260511-1.txt A patch had already been shipped out by the KDE team for the issues named: https://commits.kde.org/okular/49cccdec814b2ddb0a403b63994114f09b007a2c But checking with the Debian security patches at the time, it was not backported whatsoever, nor was it patched even in Debian Sid. Now, this problem has since been fixed, but it did make me start to worry about Debian development and whether things could be done better. All that said, I am not a developer whatsoever. I do not fully know the Debian processes for package bug checking and security patching. I had just wondered though if the Debian developer community at large were beginning to see a larger problem or if I was just jumping at shadows. I do not want to see Debian begin to lose support or become less reliable and secure. In my opinion, it has been the gold standard for Linux distros for so very long now. But anyway. If there isn't really a problem and the above incident was just a fluke, let me know and I'll leave this alone. Thank you for your time. --- Arnox, Sanctuary Administrator