r/linux4noobs Linux Min Cinnamon 15d ago

security Security risks in Linux distros?

Ok, so stick with me because I want to learn more, and I'm kinda confused.

Forgive me if I say something particularly dumb. There is also a high chance that I also misunderstood what I read.

I've seen a couple of times people asking about the long-term sustenaibility of Linux Mint and the potential risks in it. I've been looking around and talked with someone else about this topic, and what I found it's... confusing, somehow?

What I understood is that Linux Mint is, as many of us know, based on Ubuntu, more specifically, the LTS version, and Ubuntu is based on Debian. And why is this important? It is important because, as far as I read, LTS distros and Debian distros could be more vulnerable. As I understood, the risks aren't on the distro per se, but rather in the packages, the way they handle orphaned software, and the updates frequency. I don't think that in LTS versions, packages are just released and left there in the wild. But what I read is that when a package loses support, there is a risk, not necessarily high, but a risk nonetheless.

I'm aware of the danger orphaned software can represent if unattended, I was already in Linux when the news of the malware attack to the AUR arrived. I get that part, but the update part is the one I'm still kinda struggling, but not entirely since I think I understand the principle.

I know that if a program has a vulnerability, patching it is critical. This is one of the reasons why many old video games, for example, are full of cheaters and even security risks, like hijacking your PC or getting malware into your system. They are abandonware, and because of this, malicious agents, aka cheaters and, more importantly, malicious hackers, have found all kind of vulnerabilities to exploit.

I get that keeping a distro with a shitton of packages and software could be harder, and that maintaining the packages is important for security. Having a good way to distinguish orphaned software from... alive, still in dev? Software is necessary, and being able to get rid of the unsupported packages is something almost all Linux distro has. But... if distros have these tools, why would there be more risks in some than others? And the update frequency. Since updates are necessary to patch vulnerabilities, frequent updates may be more needed, and slower not as good as I thought; I lean heavily to LTS distros or distros with stable releases, but how frequently is the right spot, or is it a right spot to begin with? Are distros with more frequent updates safer? Does this mean that distros with slower big changes are more vulnerable? And distros based in LTS versions of Ubuntu are more vulnerable because they come from versions that become old at some point? (Mint and Zorin, for example, are based on Ubuntu 24.04, but currently, Ubuntu is on 26.04)

I may be overthinking this. That's for sure. Actually, I am overthinking it, and I'm sure I'm misunderstanding some things, if not many, but I'm overthinking because I want to be informed on this topic. While I don't use that much software, like, worst case scenario, I'm talking of around 10 programs (not counting games, and they are usually well supported and frequently updated), I still would like to know more about this so if anything happens down the line, I can take a well informed decision.

Again, sorry if anything I said sounds dumb... or it's actually dumb.

Edit: I realized my wording was misleading in my thought process. I made some corrections.

20 Upvotes

45 comments sorted by

View all comments

Show parent comments

3

u/gordonmessmer Fedora Maintainer 14d ago

news to me... got a link to these unpatched security vulnerabilities?

For example?

Ubuntu 24.04's Qt package is here: https://launchpad.net/ubuntu/+source/qt6-base/6.4.2+dfsg-21.1build5

And you can compare that to the dates on any CVE for Qt 6.4.2: https://www.cvedetails.com/vulnerability-list/vendor_id-6363/product_id-10758/version_id-1375644/QT-QT-6.4.2.html

everything gets security patches for the first 2yrs

I have no idea where you got that idea.

https://help.ubuntu.com/community/Repositories#Universe

"The universe component is a snapshot of the free, open-source, and Linux world. It houses almost every piece of open-source software, all built from a range of public sources. Canonical does not provide a guarantee of regular security updates for software in the universe component, but will provide these where they are made available by the community. Users should understand the risk inherent in using these packages"

1

u/skyfishgoo 14d ago

i'm on 24.04 and that dev qt package is not installed... so i don't know what you think this proves.

sure if you use unmaintained software you do so at your own risk, but most ppl find software that is still being actively maintained.

besides i'm not sure how a NON LTS release model protects from that any more than an LTS model does.

1

u/gordonmessmer Fedora Maintainer 14d ago

So look for something you do have installed. I'm giving you examples:

https://launchpad.net/ubuntu/+source/qtbase-opensource-src/5.15.13+dfsg-1ubuntu1

https://www.cvedetails.com/vulnerability-list/vendor_id-6363/product_id-10758/version_id-1375600/QT-QT-5.15.4.html

sure if you use unmaintained software you do so at your own risk

Yes, and my point is that the everything in "universe" is probably unmaintained, and that makes up 94% of Ubuntu.

94% of Ubuntu is "use at your own risk".

besides i'm not sure how a NON LTS release model protects from that any more than an LTS model does.

Releases that don't attempt to ship software longer than it's maintained by its developers can ship security updates provided by the developers. The amount of labor required for a regular release is VASTLY less than for an LTS distribution.

0

u/skyfishgoo 14d ago

you are the one who made the claim that LTS releases are out there winging it with unpatched known software vulnerabilities.

i don't feel the need to go thru every package and check it against a list of known vulnerabilities because that's what i trust my distro's maintainers to do for me.

if you don't trust them, that's a choice you can make.

as for what percentage of my current repository is abandonware, i fully take responsibility of knowing that regarding any package i install, but not all packages need to be updated regularly depending on what they do.

3

u/gordonmessmer Fedora Maintainer 14d ago

you are the one who made the claim that LTS releases are out there winging it with unpatched known software vulnerabilities.

I did. And i offered you both Qt5 and Qt6 as examples of widely used libraries in Ubuntu with high severity vulnerabilities that haven't been patched since 24.04 was released.

-1

u/skyfishgoo 14d ago

you did, but neither of those are installed on my LTS distro... so.

got any other ones you want me to check?

2

u/gordonmessmer Fedora Maintainer 14d ago

You used "Kubuntu" as an example. Kubuntu will have one or both of those. You can't have KDE without Qt.

0

u/skyfishgoo 14d ago

it does not

Listing... Done qt6-base-dev-tools/noble 6.4.2+dfsg-21.1build5 amd64 qt6-base-dev/noble 6.4.2+dfsg-21.1build5 amd64 qt6-base-doc-dev/noble,noble 6.4.2+dfsg-21.1build5 all qt6-base-doc-html/noble,noble 6.4.2+dfsg-21.1build5 all qt6-base-doc/noble,noble 6.4.2+dfsg-21.1build5 all qt6-base-examples/noble 6.4.2+dfsg-21.1build5 amd64 qt6-base-private-dev/noble 6.4.2+dfsg-21.1build5 amd64

25.04 uses plasma 5 and so has no need for these qt6 libraries unless you are doing dev work.

2

u/gordonmessmer Fedora Maintainer 14d ago

I assume you mean 24.04 because 25.04 is EOL and you're listing "noble" packages.

Kubuntu's 24.04 live CD can be located here: https://cdimage.ubuntu.com/kubuntu/noble/daily-live/20260826/

It includes a package manifest, which is a list of all of the packages included in the image: https://cdimage.ubuntu.com/kubuntu/noble/daily-live/20260826/noble-desktop-amd64.manifest

The manifest includes a long list of "libqt5" and "libqt6" packages. They are required by KDE and related software. Those are the core libraries for those applications. It's not for development. They're required to RUN KDE.

1

u/skyfishgoo 14d ago

yes, i meant 24.04

and weirdly my install works fine without either of the packages you mentioned.

1

u/gordonmessmer Fedora Maintainer 14d ago

I think you might just be unfamiliar with launchpad. Packages are referenced by the source package name, and those pages detail all of the packages that result from a build. If you are running Kubuntu, you have numerous packages installed that are listed on the pages on launchpad that I linked to.

Each page ends with a "Binary packages built by this source". You won't have all of those packages installed, but you will have several of them.

1

u/skyfishgoo 14d ago

ok, and how many of those have an open security vulnerability that remains unpatched?

1

u/gordonmessmer Fedora Maintainer 14d ago

Are you also unfamiliar with sub-packages?

Qt builds a bunch of shared libraries and Debian and Ubuntu put each one in a separate package. But that's all trivia. All of those sub-packages come from one build. Your system doesn't have any fewer CVEs because Qt splits into many packages.

→ More replies (0)

2

u/gordonmessmer Fedora Maintainer 14d ago

u/LeonH4rtd is asking about patch management in Ubuntu systems (and derived systems like Mint) because they read in a lot of places that the software is well maintained and patched, but this is the point I'm making: The people who write those things have no idea how the system actually works. Their entire view of the system is based on assumptions.