Some of them aren’t actually bugs but just “security” people wanting to get a longer epenis by flagging issues like “maximum priority, it allows to read the ssh private key!!!1!!” And then the details are like “when typing more ./ssh/id_rsa the user private key is shown, terminal should intercept and block request”
And with LLMs it’s even worse as they’re directed to find nitpicks at all costs
The following is my guess, I don’t know what the Debian project’s selection criteria for security advisories are.
Taking the first one as an example, CVE-2024-52560 is a bug that affects version 5.15 of the Linux Kernel. The oldest version of Debian that’s still in general LTS is Debian 11 which shipped with Linux 5.10. So they are still supporting releases that may be running the affected kernel and can’t upgrade the kernel for some reason, but would still benefit from some downstream patches that mitigate the exposure of the kernel bug.
Some of them are 2024 and 2025. How come they made it into this list?
Some of them aren’t actually bugs but just “security” people wanting to get a longer epenis by flagging issues like “maximum priority, it allows to read the ssh private key!!!1!!” And then the details are like “when typing
more ./ssh/id_rsathe user private key is shown, terminal should intercept and block request”And with LLMs it’s even worse as they’re directed to find nitpicks at all costs
What’s an e-penis?
An e-penis is to a penis what an e-bike is to a bike.
So… you can ride it faster?
Maybe it speeds up when you twist the handle
Don’t know, but I’m sure mine is bigger than yours.
Haha! Got me! :p
Serious answer: They’re low priority bullshit rather than practical security concerns.
“This method crashes if you intentionally feed it malformed data!!”- type of stuff.
Looking through these I don’t really see a big commonality.
Interesting that for some of them only trixie is affected, not bookworm. Maybe that’s down to bugs in newer sections of code.
https://security-tracker.debian.org/tracker/CVE-2024-52560
https://security-tracker.debian.org/tracker/CVE-2024-58094
https://security-tracker.debian.org/tracker/CVE-2024-58095
https://security-tracker.debian.org/tracker/CVE-2025-21817
https://security-tracker.debian.org/tracker/CVE-2025-22104
https://security-tracker.debian.org/tracker/CVE-2025-22108
https://security-tracker.debian.org/tracker/CVE-2025-22127
https://security-tracker.debian.org/tracker/CVE-2025-38203
https://security-tracker.debian.org/tracker/CVE-2025-38205
https://security-tracker.debian.org/tracker/CVE-2025-38206
https://security-tracker.debian.org/tracker/CVE-2025-38237
https://security-tracker.debian.org/tracker/CVE-2025-38621
https://security-tracker.debian.org/tracker/CVE-2025-39833
https://security-tracker.debian.org/tracker/CVE-2025-39925
https://security-tracker.debian.org/tracker/CVE-2025-40064
https://security-tracker.debian.org/tracker/CVE-2025-40102
https://security-tracker.debian.org/tracker/CVE-2025-40139
https://security-tracker.debian.org/tracker/CVE-2025-40168
The following is my guess, I don’t know what the Debian project’s selection criteria for security advisories are.
Taking the first one as an example, CVE-2024-52560 is a bug that affects version 5.15 of the Linux Kernel. The oldest version of Debian that’s still in general LTS is Debian 11 which shipped with Linux 5.10. So they are still supporting releases that may be running the affected kernel and can’t upgrade the kernel for some reason, but would still benefit from some downstream patches that mitigate the exposure of the kernel bug.