[1] http://metadata.ftp-master.debian.org/changelogs/main/l/linu... [2] http://metadata.ftp-master.debian.org/changelogs/main/l/linu...
[1] http://metadata.ftp-master.debian.org/changelogs/main/l/linu... [2] http://metadata.ftp-master.debian.org/changelogs/main/l/linu...
However, I've often been in situations where I reboot anyhow, because rebooting means I'm 100% confident the old code is gone, whereas if I try to get clever and avoid the restart, I'm significantly less confident. Depending on how hard it is to validate the security bug, that can be a problem.
Plus, for much of the past 20 years for many computers, if you're going to restart all services, adding in the last step for rebooting doesn't add all that significantly to the downtime. Server-class hardware often have things that make that not true (stupid RAID cards), but for everything else you were often only adding, say, 25% for the actual reboot.
Also, boot time bugs are a huge issue. They can creep during the entire time your system is up, and only show up during a reboot. Thus, if your server only has unplanned restarts, you'll only discover those bugs when you have yet another pressing issue to deal with, and also, likely at 3 in the morning on a Sunday.
So, make things better for you, and restart those servers once in a while, when things are quiet.