Malicious backdoor found in Open SSH Almost Compromised Every Linux System

https://odysee.com/@AlphaNerd:8/the-xz-backdoor-almost-compromised-every:0

FAQ on the xz-utils backdoor (CVE-2024-3094)

https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27

Reply to this note

Please Login to reply.

Discussion

Has it been patched?

update xz-utils if you are using 5.6.0 or 5.6.1 or downgrade to a version below 5.6.0, while waiting for the correction.

I keep my porthole closed, so pirates can't sail in.

New Arch Linux installation media has been released to update the included XZ packages to 5.6.1-2.

XZ Security Update for Arch Linux.

This issue with malicious code in the upstream tarballs of XZ has been fixed in packages for Arch Linux.