On Thu, Jul 23, 2026 at 11:35:54AM +0100, Kevin Chadwick wrote: > > > -------- Original Message -------- > > > Usually, audits allow for notifying as a false positive as scanning tools > > often > > have false positives or technical vulnerabilities that aren't exploitable. > > > > It sounds like these are all false positives unless your servers ssh client > > is > > connecting to some oddly managed server. > > To further the point. Debian stables security team routinely marks packages as > unaffected by a CVE or other language along the lines of rare or very unlikely > to be an issue whilst updating the package in unstable. You could ask them > about > Debian stable servers as surely they would have not required unstable to be > used. > > -- > All the best, > Kevin Chadwick
I would not be surprised if there is some Enterprise Linux Distro that fulfills this "need", and equally not surprised if there is a business relation between that and the Black Kite security scanning tool... Cheers! -- / Raimo Niskanen, Erlang/OTP, Ericsson AB

