4 ms·
This is mostly just a matter of release cycles, where Debian's is slow and the timing is unfortunate for them. Had this been discovered a few months from now (a
by ejrv 8y ago
This is mostly just a matter of release cycles, where Debian's is slow and the timing is unfortunate for them. Had this been discovered a few months from now (after the release of Debian 10, which has a modern-enough GCC version for -fstack-clash-protection), it also wouldn't have been vulnerable.
Fedora takes security very seriously and I adore the distro in part for being on the bleeding edge, but this has more to do with where these distros happen to be in their release cycles than how seriously they take security.