upvote
The vast majority of kernel vulnerabilities aren't backported to end-of-life devices. Special cases are made for certain vulnerabilities with a lot of media coverage. Firmware, kernel drivers, userspace drivers and HALs on end-of-life devices go without patches in general.
reply
They patched CVE-2026-43499 even for out of support kernels[1] so that's something. The bigger problem is CVEs in proprietary components (drivers, blobs, firmware).

[1] eg. https://review.lineageos.org/q/b309b56b8cca20dcf6f678777d3ac...

reply
That's very misleading since the vast majority of serious Linux kernel vulnerabilities aren't patched for these end-of-life devices. That vulnerability patched due to media coverage based on their policy to do so. It's no more severe than many of the unpatched ones.
reply
That's honestly impressive, enough security for a locked down backup phone.
reply
It's very misleading since the vast majority of serious Linux kernel vulnerabilities aren't patched for these end-of-life devices. That vulnerability patched due to media coverage based on their policy to do so. It's no more severe than many of the unpatched ones.
reply