Conversation

Replying to
They normally don't fix anything other than security bugs which means they're unwilling to ship point releases. Exceptions can be made but it would normally only happen as part of a Debian point release if at all. It has to be approved by their release team. It's pretty broken.
1
1
Replying to and
If there are security bugs without a CVE assignment then it's highly unlikely it will get backported. Of course, most security-relevant fixes don't get a CVE assignment and there's always a huge backlog of missing CVE fixes including packages where they give up and stop doing it.
1
1
Replying to and
It's a very naive way of doing security fixes ignoring that most won't get a CVE assigned but that's Debian. It's particularly bad for the Linux kernel but they do seem to be shipping the upstream LTS releases in OS point releases now. It's possible to convince them to do it.
2
2