Post #1870541
2026-05-02 02:12 UTC
If you debootstrap a brand new trixie install today, you will get not just a vulnerable kernel but also a vulnerable libssl3t64 missing patches for 6 CVEs including a heap buffer overflow and a use after free.
I'm not really a debian expert but this seems... not.. good?
Replies (1)
-
@Leah@macaw.social 2026-05-02 04:18
@hailey@hails.org debootstrap does the bare minimum for booting. You're expected to update the sources.list files and do an apt update and apt dist-upgrade after to configure.