Updating Debian

graylion

Dabbler
Joined
Dec 28, 2019
Messages
32
Do I update Debian under scale myself or do I leave well enough alone and wait for updates from iX to come down?
 

jgreco

Resident Grinch
Joined
May 29, 2011
Messages
18,680
What is "Debian"?

This is an appliance OS. You don't touch it, any more than you would log in to your cable modem, television, microwave, cell phone, wireless access point, etc., and try to "upgrade Debian" on these devices. Attempting to do so could very well damage the appliance or its functionality.
 

graylion

Dabbler
Joined
Dec 28, 2019
Messages
32
Debian is the OS that Scale is running on. And it has a vulnerability that a script kiddy could exploit. CVE-2022-0847 to be precise. So, that should be patched.
 

jgreco

Resident Grinch
Joined
May 29, 2011
Messages
18,680
Debian is the OS that Scale is running on.

Totally missing the point. TrueNAS SCALE is not a generic Linux operating system, certainly not one called "Debian". Just because something started out as based on Debian doesn't mean that it is still credibly Debian or can be treated as a generic Debian system.

CVE-2022-0847

Which, if you look at it, talks about an exploit that appears to require local access to the system. If you are letting "skript kiddiez" have shell logins into your system, you might want to stop. There are likely far more serious risks present in the system if you can log in and inspect the code and configuration database. Here on the forums, we don't even recommend treating the NAS platform as secure at the network level. I doubt CVE-2022-0847 is causing anyone over at iXsystems to stop what they're doing and grind out a patch.
 
Top