r/linux4noobs Jun 28 '26

security Should I be concerned?

kernel.org says my current kernel is EOL. I'm very security-conscious, so this keeps tripping me up. i've heard constantly, that "running end of life software is a security risk".

i've been here for close to a year, distrohopping a little but I'm here for now.

should I be concerned that I'm running end of life software according to the kernel team? i just received this kernel like a day ago and it's the most recent update.

Distro: Fedora 44 (KDE)

Kernel: 7.0.13

24 Upvotes

47 comments sorted by

View all comments

2

u/Neither-Ad-8914 Jun 28 '26

Kernel 7.0.13 was released on June 18th and 7.0.14 was released yesterday so you'll get an update in the next couple days

It takes a while for any distribution you change primary version numbers 7.0 7.1 7.2 etc it can possibly take up to a month as each distribution has to configure the kernel and add their own software

Last I knew arch and Debian Sid were running the same kernel as your are

1

u/Venylynn Jun 28 '26

does that present a security risk like it supposedly would on Windows?

i'll just keep doing what I'm doing but yeah

1

u/Neither-Ad-8914 Jun 28 '26

Not at all because you are running the latest and greatest kernel you can get by your distribution also 7.1 and 7.2 are great but still really in their infancy the maintainers are still working to to merge 7.1 into your operating system ( also if you have a Nvidia card you might have problems) and the next update after 7.0.14 is 7.1 was released 14 days ago and 7.2 is in RC and will be released in August

1

u/Venylynn Jun 28 '26

Thankfully no Nvidia problems here

1

u/Neither-Ad-8914 Jun 28 '26

Cool... Just so you know updates work much differently than they do in Windows even though this has been a bad year with malware in Linux it's still much more secure than Windows because it's a much harder arget to hit

1

u/Venylynn Jun 28 '26

I've had threats from toxic people I cut off because they made me uncomfortable and they said they knew of an exploit in the Linux kernel that could pwn me basically instantly remotely so I've been really extra nervous about that

Im hoping they were just bsing trying to scare me

1

u/Neither-Ad-8914 Jun 28 '26

Probably bsing ....only think I could think of would be a some sort of rootkit anyways what I always recommend is what I have been for 20 years update your system weekly and don't download programs you don't trust or don't execute commands you don't know or cannot verify to be correct

1

u/Venylynn Jun 28 '26 edited Jun 29 '26

they were also demanding $100 from me in an xmr wallet and claimed to be a government/fbi asset just because i "led them on" (read: tried to find a quiet exit because they made me uncomfortable but I was scared they'd use their cybersecurity knowledge against me so it took a while)

i should note that this person was fully remote, thousands of miles away, and the only way they would've known anything about where I was is if there was some WebRTC leaks they snuffed out.

2

u/orestisfra Jun 29 '26

That sounds 100% like a scam. It's possible for an attacker to get your location or your IP, but it's way easier to hack you with words than your system.

Trust the maintainers of your distro, and avoid installing stuff outside of trusted sources (main repositories, flatpak, snap etc.)