this post was submitted on 29 Mar 2024
26 points (100.0% liked)

technology

23218 readers
1 users here now

On the road to fully automated luxury gay space communism.

Spreading Linux propaganda since 2020

Rules:

founded 4 years ago
MODERATORS
top 3 comments
sorted by: hot top controversial new old
[–] PorkrollPosadist@hexbear.net 8 points 1 year ago* (last edited 1 year ago) (1 children)

Debian security advisory - impacts Testing and Unstable. Stable unaffected. (Debian is upstream of A LOT of other distributions, such as Ubuntu)

Red Hat CVE - impacts Fedora 41 and Rawhide

Arch Linux announcement - Impacted, upgrade immediately

Gentoo bug - Package was in the Gentoo repository, masked by ~arch (unstable) keyword. Children who wildcard-unmask everything are impacted.

Surely there are more.

This is pretty bad.

[–] Anafabula@discuss.tchncs.de 2 points 1 year ago* (last edited 1 year ago)

openSUSE - impacts Tumbleweed & MicroOS

NixOS - Unstable probably not affected?

[–] trompete@hexbear.net 5 points 1 year ago

Perhaps worth mentioning: Some unknown person added malware to their tarball releases, specifically to backdoor ssh, which on most Linux distros was patched to load some systemd library, which in turn loads liblzma.