Uh, is it normal for an automated scanner to be unaware of patched packages?

Like how OpenSSH 9.2p1 is vulnerable to CVE-2023-38408 but the Debian version 1:9.2p1-2+deb12u5 is patched. But the security scanner sees the "9.2p1" string and sounds the alarm.

security-tracker.debian.org/tr

Is this a common problem for people running Debian servers?

0

If you have a fediverse account, you can quote this note from your own instance. Search https://social.tchncs.de/users/teleclimber/statuses/114224649441602465 on your instance and quote it. (Note that quoting is not supported in Mastodon.)