Lesson 1 of 1 in Patching That Happens
The Fix Nobody Applied
Most breaches walk in through a hole that was fixed months earlier and never patched. Automatic security updates close that gap while you sleep — but only if the box also reboots, because a kernel fix that never restarts is a fix that never took.
2 min read
Not yet reviewed
I will update the server when I get a chance — every few weeks, maybe.
"Every few weeks" is the window I live in. I do not need a clever new exploit. I need the published one for the version you are still running, and a scanner that finds everyone who has not patched. You are on that list the day after the fix ships, not the day of the attack.
Known, patched, and still open
The dangerous vulnerability is rarely secret. It is public, it has a fix, and it has a number — and the gap that gets exploited is the one between the fix being released and you applying it. In 2017 the Equifax breach walked through a web-framework hole that had a patch available for months before the attack. The exploit was not the story. The unapplied patch was.
So patching cannot depend on you remembering, because a schedule that lives in your head is a schedule that slips the week you are busy. It has to happen without you. On Debian and Ubuntu, unattended-upgrades installs security updates automatically, every day, and that single change closes most of the window an attacker needs.
# enable automatic security updates, then confirm the schedule exists
apt install unattended-upgrades
dpkg-reconfigure -plow unattended-upgrades
# the honest part: some fixes only take effect after a restart
apt install needrestart # tells you what still runs old code
- Line 4A kernel or C-library fix is downloaded and installed, but the running system keeps using the old code in memory until it restarts. Patched on disk is not patched in fact.
Note
This is the piece people miss: unattended-upgrades without a reboot window is not patching. Set an automatic reboot in the quiet hours, or at least let something tell you when a restart is owed — otherwise your box reports itself fully patched while still running the vulnerable kernel it downloaded the fix for weeks ago.
Automatic reboots feel dangerous — what if the box does not come back up at 4am with nobody watching? Is the risk worth it?
This is the unattended-upgrades config. Turn on the automatic reboot: append a line so the file contains Unattended-Upgrade::Automatic-Reboot "true";.