Questions about kernel CVEs from Debian DSAs (DSA-6126-1 / DSA-6127-1) and IPFire Core Update 199

I’m evaluating whether IPFire Core Update 199 (kernel Linux 6.12.58 in the Core Update 199 rebase) is affected by the CVEs listed in Debian Security Advisories DSA-6126-1 and DSA-6127-1.

Many CVEs listed in both DSAs affect code present in the 6.12.x line, those CVEs would be applicable to an unpatched upstream 6.12.58 kernel.

IPFire’s Core Update 199 states a rebase on Linux 6.12.58 and includes IPFire-specific patches. Whether each CVE actually affects IPFire depends on whether IPFire backported the corresponding fixes or applied other mitigations.

Any recommended immediate mitigations for administrators running IPFire 199 while fixes are confirmed (e.g., configuration hardening, service restrictions)?

Hello Da,

those DSAs a listing hundreds of CVEs each. So I suppose we will have to assume that IPFire is vulnerable to at least one of them. That is just pure statistics.

How to mitigate? That is impossible to say without identifying which CVEs would apply - if any.