https://security-tracker.debian.org/tracker/CVE-2024-47176, archive

As of 10/1/24 3:52 UTC time, Trixie/Debian testing does not have a fix for the severe cupsd security vulnerability that was recently announced, despite Debian Stable and Unstable having a fix.

Debian Testing is intended for testing, and not really for production usage.

https://tracker.debian.org/pkg/cups-filters, archive

So the way Debian Unstable/Testing works is that packages go into unstable/ for a bit, and then are migrated into testing/trixie.

Issues preventing migration: ∙ ∙ Too young, only 3 of 5 days old

Basically, security vulnerabilities are not really a priority in testing, and everything waits for a bit before it updates.

I recently saw some people recommending Trixie for a “debian but not as unstable as sid and newer packages than stable”, which is a pretty bad idea. Trixie/testing is not really intended for production use.

If you want newer, but still stable packages from the same repositories, then I recommend (not an exhaustive list, of course).:

  • Opensuse Leap (Tumbleweed works too but secure boot was borked when I used it)
  • Fedora

If you are willing to mix and match sources for packages:

  • Flatpaks
  • distrobox — run other distros in docker/podman containers and use apps through those
  • Nix

Can get you newer packages on a more stable distros safely.

  • Lvxferre@mander.xyz
    link
    fedilink
    arrow-up
    3
    ·
    34 minutes ago

    Yeah, using Testing directly is a bad idea. Instead pick a distro based on Testing - like LMDE (Linux Mint Debian Edition); or if you really need bleeding edge use Sid instead, but be aware that it was named after the child who breaks toys for a reason.

  • 0x0@programming.dev
    link
    fedilink
    arrow-up
    4
    ·
    2 hours ago

    Stick to stable for production. Patches for vulnerabilities will go to stable asap. That’s where you want them, not testing or unstable.

    • al4s
      link
      fedilink
      arrow-up
      4
      arrow-down
      4
      ·
      6 hours ago

      I mean you’d still expect that critical security fixes would land in testing, no?

      • uiiiq@lemm.ee
        link
        fedilink
        arrow-up
        8
        ·
        5 hours ago

        Why bother? Backporting security updates or updating packages is work and in case of debian often unpaid. Trixie is for testing new packages and configurations, does not make a ton of sense to keep everything up to date.

      • lurch (he/him)@sh.itjust.works
        link
        fedilink
        arrow-up
        1
        arrow-down
        1
        ·
        5 hours ago

        it would be nice, but i only expect them to arrive with the regular package updates, i.e. when a new version of cups with the fix in it is released, not an extra quicker fix from the distro maintainer.

  • Scoopta@programming.dev
    link
    fedilink
    arrow-up
    14
    ·
    7 hours ago

    How are fedora or SUSE valid alternatives “from the same repos”? They’re not even based on Debian or Debian repos?

  • toasteecup@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    13
    ·
    7 hours ago

    I would sooner use Windows before using Fedora. Fortunately, Linux Mint or Ubuntu exist instead.

    • L3ft_F13ld!@links.hackliberty.org
      link
      fedilink
      arrow-up
      7
      ·
      6 hours ago

      I’m not a fan of Fedora either, but it’s still linux. Always better than Windows, unless you have some very serious reason for disliking it that much.

      • toasteecup@lemmy.world
        link
        fedilink
        English
        arrow-up
        6
        arrow-down
        2
        ·
        6 hours ago

        Not sure if anyone else will think it’s good enough but I do.

        Redhat as a company acts like a parasite on open source, producing a product that is garbage which they then charge money for their support plans. Have an issue with their offering? Fuck you. In addition to that, I absolutely beyond a doubt HATE how they do their filesystem and just willy nilly do whatever the fuck they think is best instead of following community established patterns and designs. Top it off with, who was the first to adopt systems? Redhat.

        Stepping away slightly from that, have you dug into ansible’s internal before? Actual fucking idiot decisions. Have an issue with tower or AAP (stupid fucking name) good luck getting it fixed. According to their documentation you can have vaulted vars in a cars file with plaintext cars. According to reality, that’s causes intermittent failures and has for the past 8 years. There have been SEVERAL GitHub issues submitted but it’s still not fixed.

        Fuck redhat and fuck their bullshit like fedora. If I wanted to use a garbage distro, I’d at least want to use one that isn’t pretending to be decent.