To apply a Linux kernel security update safely, use the supported repositories and package manager for your exact distribution and release, review the proposed changes, plan for recovery, install the update, and reboot when a new kernel must be loaded. Afterward, run uname -r to check which kernel is running and verify that essential services and network access recovered.
Before updating, identify the system and its supported update source
First record the distribution, release, architecture, and role of the machine: desktop, local server, cloud image, or remote production host. Confirm that the release is supported and that its kernel comes from the distribution or another repository the system is intended to use. Security coverage can differ by release and package component, so a generic Linux command cannot establish whether a particular machine is supported or fully patched.
Use the package manager and package names documented for that distribution and release. Ubuntu manages kernel security updates through its packaging and security maintenance; Debian 13 (trixie) documents apt and linux-image packages; RHEL 9 manages RPM-packaged kernels with DNF. Do not mix instructions between these systems or substitute an upstream kernel build unless the host is deliberately managed that way and you understand the support and boot implications. See Ubuntu security updates, the Debian 13 release notes, and Red Hat’s RHEL 9 kernel documentation.
Review and install the kernel update
Refresh package metadata and inspect the proposed changes with the system’s normal package tools and local change-control process. Then install the security update from the supported repositories. Exact commands depend on the release, repository configuration, and whether the kernel is managed by the distribution or another vendor; use that system’s current documentation rather than copying a command for a different Linux family.
#1 Best Overall
Debian 13: check the kernel metapackage
Debian 13’s release notes recommend having a suitable linux-image metapackage installed so future upgrades can bring in updated kernels. Check the installed metapackages and follow the release notes’ package-selection guidance if one is absent. This advice is specific to Debian 13’s documented upgrade process; do not assume it applies unchanged to other Debian releases or customized kernels.
Ubuntu: distinguish package updates from Livepatch
Install security updates through Ubuntu’s package and security-maintenance channels for the installed release and package component. Canonical Livepatch is a separate, limited service; enabling it does not enable automatic APT security updates. Check Canonical’s Livepatch documentation for supported kernels and current service scope.
Rank #2
RHEL 9: use the documented DNF and RPM process
RHEL 9’s kernel is packaged as RPMs and managed with DNF. Use the version-specific Red Hat kernel documentation and security advisories to review package state and follow the supported update procedure; do not infer security status from a version string alone.
Plan the reboot and recovery before applying it
Installing a kernel package does not necessarily make that kernel the one currently running. When an update installs a new kernel, a normal reboot is generally needed to boot into it. Schedule the reboot in an appropriate maintenance window and consider the possible pre-reboot issues described in the Debian 13 release notes.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
For a remote server, confirm how you will recover access if the host fails to boot or the network does not return. Before restarting, check that you can reach a provider or hardware console, understand the bootloader’s default selection, know which services depend on the machine, and have a way to verify connectivity afterward. Coordinate the maintenance window and ensure important workloads can be restarted or recovered. Debian’s security guidance has also emphasized verifying a successful boot and restored networking after remote kernel updates; the operational risk makes a recovery path important even when following a newer release’s procedure.
Reboot when required, then check the running kernel
After the update, reboot if a newly installed kernel needs to be loaded or the vendor’s update notice calls for one. Once the host is back, run:
Rank #4
uname -r
The command reports the release of the kernel currently running. Compare that result with the expected release from the installed kernel package and the distribution’s package information. Red Hat documents the correspondence between RHEL 9’s uname -r output and its kernel RPM; consult package details and release documentation to interpret it.
If the output still identifies the earlier kernel, the system has not booted into the newly installed one. Check the reboot state and boot selection using the distribution’s documented procedures. Also confirm that essential services, storage, and network connectivity have recovered.
Free tools Windows power users keep installed
One-click scans. No signup required.
A kernel release string by itself does not prove that a specific CVE is fixed or that every security update is installed. Distributions may backport fixes, and supported live-patching services may apply certain changes without changing the reported release string. For a vulnerability-specific determination, check the relevant vendor advisory and installed package state.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.When live patching can—and cannot—replace an immediate reboot
Live patching can help maintain continuity when a distribution supports the kernel and vulnerability in question, but its coverage is limited and vendor-specific. Canonical says its Livepatch service covers selected high- and critical-severity kernel vulnerabilities on supported Canonical-released kernels. It does not replace APT security updates or every kernel package update. Kernel upgrades, driver updates, non-security fixes, performance improvements, new features, unsupported cases, and vulnerabilities that cannot be live-patched may still require installing an update and rebooting. A Livepatch notice may also indicate that a reboot is required.
Canonical states: “Live kernel patching is not sufficient when you need to upgrade your kernel to a newer version — a reboot is required in that case.” Check the vendor’s supported-kernel list and service notices before relying on live patching, and do not assume Canonical’s eligibility rules apply to another distribution or kernel build.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →

