Greetings. Marc Haber - 03.09.26, 10:40:04 CEST: > On Thu, Sep 03, 2026 at 08:05:25AM +0000, LAURENT Florian (Externe) > wrote: > >As a security auditer, I would like to identify when a specific kernel > >version has been released. > What exactly do you mean by "released"? Do you mean the upstream release > on kernel.org, or the upload of a Debian package containing said kernel > to unstable, or the release of the Debian stable distribution > contianing said kernel? > > And with that, we have not yet started to look at backports, stable > point releases, security and stable updates, ... > > You need to be familiar with how Debian works to make real use of that > information. What is the object of your question?
And what for? What is the actual aim here? All of this information is readily available online. IMHO it is not even hard to find. I would claim that a security auditor would be able to find resources such as¹: - upstream: https://kernel.org or via RSS: http://kernel.org/kdist/rss.xml - Debian packaged kernels if package name is known: https://tracker.debian.org - In addition to that mailing lists like this one or debian-devel-changes, debian-backport-changes or search for "linux security update" in debian- security-announce mailing list just to name a few. Or even the changelog of an installed kernel package. Of course this list is not complete. In addition to that there is debsecan and apticron. Depending on which source you use there might be some inaccuracy, cause for example a date in package changelog does not reflect when a new kernel packages actually is available on a certain mirror. And when it is, you still do not know when the package was installed on a certain system, unless you look there. Not all of the above is specific to just kernels. However the kernel is by no means the only relevant component when it is about assessing the security status of a Debian system. [1] Using the search engine of your choice. I bet none of the resources mentioned above are really difficult to find if willing to invest some time. Best, -- Martin

